Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7g9-rp3g-mgfg

Опубликовано: 06 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

Impact

The unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module.

Patches

This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30. Users should upgrade all packages.

Workarounds

If users cannot upgrade, they can remove the @backstage/plugin-catalog-backend-module-unprocessed module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints
without upgrading.

Пакеты

Наименование

@backstage/plugin-catalog-unprocessed-entities-common

npm
Затронутые версииВерсия исправления

< 0.0.15

0.0.15

Наименование

@backstage/plugin-catalog-unprocessed-entities

npm
Затронутые версииВерсия исправления

< 0.2.30

0.2.30

Наименование

@backstage/plugin-catalog-backend-module-unprocessed

npm
Затронутые версииВерсия исправления

< 0.6.11

0.6.11

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
redhat
3 месяца назад

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

CVSS3: 4.3
nvd
3 месяца назад

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863