Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44374

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

A flaw was found in Backstage, an open framework for building developer portals. The system's unprocessed entity endpoints lack proper authorization checks. This allows any authenticated user to access sensitive entity records they should not have access to, leading to unauthorized information disclosure.

Отчет

This Moderate information disclosure flaw in Backstage's unprocessed entity endpoints, which allows authenticated users to access unauthorized records, does not affect Red Hat Developer Hub. The vulnerable backend module is not implemented in Red Hat's supported configurations of the product. @backstage/plugin-catalog-unprocessed-entities may be present as an unused dependency of the app-next workspace, but without the corresponding backend module the affected endpoints are not exposed and the product is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2477466Backstage: @backstage/plugin-catalog-backend-module-unprocessed: @backstage/plugin-catalog-unprocessed-entities-common: @backstage/plugin-catalog-unprocessed-entities: Backstage: Information disclosure due to missing authorization checks

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

CVSS3: 4.3
github
3 месяца назад

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

EPSS

Процентиль: 7%
0.0017
Низкий

4.3 Medium

CVSS3