VDB
Sign up
MEDIUM4.3

GHSA-p7g9-rp3g-mgfg

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

Quick fix

GHSA-p7g9-rp3g-mgfg — @backstage/plugin-catalog-unprocessed-entities-common: upgrade to the fixed version with the command below.

npm install @backstage/plugin-catalog-unprocessed-entities-common@0.0.15

Details

### Impact

The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. ### Patches This is patched in `@backstage/plugin-catalog-backend-module-unprocessed` version 0.6.11, `@backstage/plugin-catalog-unprocessed-entities-common` version 0.0.15 and `@backstage/plugin-catalog-unprocessed-entities` version 0.2.30. Users should upgrade all packages. ### Workarounds If users cannot upgrade, they can remove the `@backstage/plugin-catalog-backend-module-unprocessed` module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints without upgrading.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/plugin-catalog-unprocessed-entities-common
Introduced in: 0Fixed in: 0.0.15
Fixnpm install @backstage/plugin-catalog-unprocessed-entities-common@0.0.15
npm/@backstage/plugin-catalog-unprocessed-entities
Introduced in: 0Fixed in: 0.2.30
Fixnpm install @backstage/plugin-catalog-unprocessed-entities@0.2.30
npm/@backstage/plugin-catalog-backend-module-unprocessed
Introduced in: 0Fixed in: 0.6.11
Fixnpm install @backstage/plugin-catalog-backend-module-unprocessed@0.6.11

References