fix(deps): update dependency @backstage/plugin-catalog-backend-module-unprocessed ( 0.6.6 ➔ 0.6.11 ) [security] #83

Open
renovate wants to merge 1 commit from renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@backstage/plugin-catalog-backend-module-unprocessed (source) 0.6.6 → 0.6.11 age adoption passing confidence

🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so minimumReleaseAge cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

CVE-2026-44374 / GHSA-p7g9-rp3g-mgfg

More information

Details

Impact

The unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is
an information disclosure vulnerability affecting Backstage installations using this module.

Patches

This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30. Users should upgrade all packages.

Workarounds

If users cannot upgrade, they can remove the @backstage/plugin-catalog-backend-module-unprocessed module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints
without upgrading.

Severity

  • CVSS Score: 4.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/plugin-catalog-backend-module-unprocessed)

v0.6.11

Compare Source

Patch Changes

v0.6.10

Compare Source

Patch Changes

v0.6.9

Compare Source

Patch Changes

v0.6.8

Compare Source

Patch Changes

v0.6.7

Compare Source

Patch Changes

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@backstage/plugin-catalog-backend-module-unprocessed](https://backstage.io) ([source](https://github.com/backstage/backstage/tree/HEAD/plugins/catalog-backend-module-unprocessed)) | [`0.6.6` → `0.6.11`](https://renovatebot.com/diffs/npm/@backstage%2fplugin-catalog-backend-module-unprocessed/0.6.6/0.6.11) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@backstage%2fplugin-catalog-backend-module-unprocessed/0.6.11?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@backstage%2fplugin-catalog-backend-module-unprocessed/0.6.11?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@backstage%2fplugin-catalog-backend-module-unprocessed/0.6.6/0.6.11?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@backstage%2fplugin-catalog-backend-module-unprocessed/0.6.6/0.6.11?slim=true) | 🔒 **Security update**: prioritize review and verify the vulnerable component is actually deployed. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so `minimumReleaseAge` cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks [CVE-2026-44374](https://nvd.nist.gov/vuln/detail/CVE-2026-44374) / [GHSA-p7g9-rp3g-mgfg](https://github.com/advisories/GHSA-p7g9-rp3g-mgfg) <details> <summary>More information</summary> #### Details ##### Impact The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. ### Patches This is patched in `@backstage/plugin-catalog-backend-module-unprocessed` version 0.6.11, `@backstage/plugin-catalog-unprocessed-entities-common` version 0.0.15 and `@backstage/plugin-catalog-unprocessed-entities` version 0.2.30. Users should upgrade all packages. ### Workarounds If users cannot upgrade, they can remove the `@backstage/plugin-catalog-backend-module-unprocessed` module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints without upgrading. #### Severity - CVSS Score: 4.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-p7g9-rp3g-mgfg](https://github.com/backstage/backstage/security/advisories/GHSA-p7g9-rp3g-mgfg) - [https://nvd.nist.gov/vuln/detail/CVE-2026-44374](https://nvd.nist.gov/vuln/detail/CVE-2026-44374) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-p7g9-rp3g-mgfg) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>backstage/backstage (@&#8203;backstage/plugin-catalog-backend-module-unprocessed)</summary> ### [`v0.6.11`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-backend-module-unprocessed/CHANGELOG.md#0611-next0) [Compare Source](https://github.com/backstage/backstage/compare/168d7cc9eb2af6902ee21dd37f25b8fc0bc05438...61fbc82cb8dba0fa62e5ac8861e2dbbedb229f32) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.1-next.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.1-next.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.1-next.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.8.1-next.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.1-next.0 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.15-next.0 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.9-next.0 ### [`v0.6.10`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-backend-module-unprocessed/CHANGELOG.md#0610) [Compare Source](https://github.com/backstage/backstage/compare/7918ae477c7b98b77c79249836898b342e41df29...168d7cc9eb2af6902ee21dd37f25b8fc0bc05438) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.9.0 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.7.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.8.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.2.0 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.14 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.8 ### [`v0.6.9`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-backend-module-unprocessed/CHANGELOG.md#069) [Compare Source](https://github.com/backstage/backstage/compare/c4d19ed1b6953eafbc30edc223c88bea6d5ef76b...7918ae477c7b98b77c79249836898b342e41df29) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.8.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.1.0 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.7 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.7.7 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.14 ### [`v0.6.8`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-backend-module-unprocessed/CHANGELOG.md#068) [Compare Source](https://github.com/backstage/backstage/compare/d03fd681a91928c65419df989d9fc4adef3a2dba...c4d19ed1b6953eafbc30edc223c88bea6d5ef76b) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.0.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.7.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.13 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.6 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.13 ### [`v0.6.7`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-backend-module-unprocessed/CHANGELOG.md#067) [Compare Source](https://github.com/backstage/backstage/compare/cd79f31c8ccb6d611bac2cfb13a019a555132011...d03fd681a91928c65419df989d9fc4adef3a2dba) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.10 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.6.0 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.12 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;1.20.1 </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInNlY3VyaXR5IiwidHlwZS9wYXRjaCJdfQ==-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability:renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch main
git merge --squash renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch main
git merge --ff-only renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git switch main
git merge renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability
git push origin main
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/backstage-application!83
No description provided.