5
CVE-2026-106561
- EPSS -
- Veröffentlicht 07.10.2026 14:52:16
- Zuletzt bearbeitet 07.10.2026 17:16:51
- Erkennungen
Backstage: Sensitive information disclosure in Kubernetes resource queries
Backstage is an open framework for building developer portals. Prior to 0.21.9, the @backstage/plugin-kubernetes-backend package is affected by sensitive information disclosure in kubernetes resource queries. An authenticated user holding the standard Kubernetes resource read permission could retrieve sensitive values that the Kubernetes plugin is designed to mask, potentially exposing credentials and other confidential material held in the connected clusters. Exposure is limited to resources that the Backstage service account is permitted to read and that match the targeted catalog entity's namespace and label selector. Deployments whose cluster credentials do not grant read access to these resources are unaffected. This issue is fixed in version 0.21.9.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerbackstage
≫
Produkt
backstage
Version
< 1.54.2
Status
affected
Hersteller@backstage
≫
Produkt
plugin-kubernetes-backend
Version
< 0.21.9
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/backstage/backstage/security/advisories/GHSA-p795-mqf2-36mf
https://github.com/backstage/backstage/commit/388926ae5734bc20bd6a1520d02896be834f6527
https://github.com/backstage/backstage/releases/tag/v1.54.2