Vulnerability GHSA-7hfw-grcm-cqm6
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
October 07, 2026 at 05:58 PM UTC
Backstage: Incorrect authorization in scaffolder task listing
0.0.0-nightly-202010102951 - 4.1.0-next.0
0.0.0-nightly-202010102951 - 4.1.0-next.0
Summary
Backstage: Incorrect authorization in scaffolder task listing
Details
Impact
An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users who are permitted to view all tasks.
- Avoid placing sensitive values in template input parameters until the patched package is deployed.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 hours ago
Backstage may expose sensitive information in Scaffolder task failure events
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
Medium Risk
3 hours ago
Backstage has sensitive information exposure in scaffolder task logs
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
Medium Risk
3 hours ago
Backstage has improper input validation in scaffolder task list ordering
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
Medium Risk
6 months ago
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
3.1.0 - 3.1.4 GHSA-8wq8-6859-qx77
3.1.0 - 3.1.4 GHSA-8wq8-6859-qx77
Low Risk
7 months ago
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
0.0.0-nightly-202010102951 - 3.1.4-next.0 GHSA-8qp7-fhr9-fw53
0.0.0-nightly-202010102951 - 3.1.4-next.0 GHSA-8qp7-fhr9-fw53
Impacted packages
Timeline
Published
1 hour ago
October 07, 2026 at 05:58 PM UTC
Fixed (4.1.0)
1 month ago
August 28, 2026 at 08:20 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 06:15 PM UTC