GHSA-p7g9-rp3g-mgfg
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
Quick fix
GHSA-p7g9-rp3g-mgfg — @backstage/plugin-catalog-unprocessed-entities-common: upgrade to the fixed version with the command below.
npm install @backstage/plugin-catalog-unprocessed-entities-common@0.0.15Details
### Impact
The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. ### Patches This is patched in `@backstage/plugin-catalog-backend-module-unprocessed` version 0.6.11, `@backstage/plugin-catalog-unprocessed-entities-common` version 0.0.15 and `@backstage/plugin-catalog-unprocessed-entities` version 0.2.30. Users should upgrade all packages. ### Workarounds If users cannot upgrade, they can remove the `@backstage/plugin-catalog-backend-module-unprocessed` module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints without upgrading.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.0.15npm install @backstage/plugin-catalog-unprocessed-entities-common@0.0.150Fixed in: 0.2.30npm install @backstage/plugin-catalog-unprocessed-entities@0.2.300Fixed in: 0.6.11npm install @backstage/plugin-catalog-backend-module-unprocessed@0.6.11