
@backstage/backend-defaults is vulnerable to Accidental exposure of sensitive info possible



@backstage/backend-defaults js

AIKIDO-2024-10342: @backstage/backend-defaults is vulnerable to Accidental exposure of sensitive info possible in versions 0.1.0 - 0.5.0.

Accidental exposure of sensitive info possible
Vuln in 0.1.0 - 0.5.0
Fixed in 0.5.1
No CVE available

Affected versions of the package are vulnerable to accidental exposure of sensitive info of a BackstageCredentials object.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

How can it be fixed?

Upgrade @backstage/backend-defaults library to patch version.

Background info

