Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0292 | @backstage/backend-app-api leaks GitLab access tokens |
Github GHSA |
GHSA-86rg-pf4c-5grg | @backstage/backend-app-api leaks GitLab access tokens |
Solution
No solution given by the vendor.
Workaround
To mitigate this vulnerability until you can update to RHDH 1.1, ensure that the base64 encoded GitLab token does not contain a newline character at the end. Removing the newline from the token prevents the unintended disclosure of the access token through the frontend.
Fri, 05 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhdh:1.1::el9 | |
| References |
|
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-05T12:00:26.300Z
Reserved: 2023-12-19T10:23:24.260Z
Link: CVE-2023-6944
Updated: 2024-08-02T08:42:08.676Z
Status : Modified
Published: 2024-01-04T10:15:11.517
Modified: 2025-09-05T12:15:31.357
Link: CVE-2023-6944
OpenCVE Enrichment
No data.
EUVD
Github GHSA