Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44374

Опубликовано: 14 мая 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:backstage\/plugin-catalog-backend-module-unprocessed:*:*:*:*:*:node.js:*:*
Версия до 0.6.11 (исключая)
cpe:2.3:a:linuxfoundation:backstage\/plugin-catalog-unprocessed-entities:*:*:*:*:*:node.js:*:*
Версия до 0.2.30 (исключая)
cpe:2.3:a:linuxfoundation:backstage\/plugin-catalog-unprocessed-entities-common:*:*:*:*:*:node.js:*:*
Версия до 0.0.15 (исключая)

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
redhat
3 месяца назад

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

CVSS3: 4.3
github
3 месяца назад

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863