fix(deps): update dependency @backstage/plugin-catalog-backend-module-unprocessed ( 0.6.6 ➔ 0.6.11 ) [security] #83
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/backstage-application!83
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/npm-backstage-plugin-catalog-backend-module-unprocessed-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.6.6→0.6.11🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — sominimumReleaseAgecannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
CVE-2026-44374 / GHSA-p7g9-rp3g-mgfg
More information
Details
Impact
The unprocessed entities read endpoints in
@backstage/plugin-catalog-backend-module-unprocesseddo not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This isan information disclosure vulnerability affecting Backstage installations using this module.
Patches
This is patched in
@backstage/plugin-catalog-backend-module-unprocessedversion 0.6.11,@backstage/plugin-catalog-unprocessed-entities-commonversion 0.0.15 and@backstage/plugin-catalog-unprocessed-entitiesversion 0.2.30. Users should upgrade all packages.Workarounds
If users cannot upgrade, they can remove the
@backstage/plugin-catalog-backend-module-unprocessedmodule from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpointswithout upgrading.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-catalog-backend-module-unprocessed)
v0.6.11Compare Source
Patch Changes
v0.6.10Compare Source
Patch Changes
v0.6.9Compare Source
Patch Changes
v0.6.8Compare Source
Patch Changes
v0.6.7Compare Source
Patch Changes
Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.