Vulnerability GHSA-7hfw-grcm-cqm6

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
October 07, 2026 at 05:58 PM UTC
Backstage: Incorrect authorization in scaffolder task listing
0.0.0-nightly-202010102951 - 4.1.0-next.0
0.0.0-nightly-202010102951 - 4.1.0-next.0

Summary

Backstage: Incorrect authorization in scaffolder task listing

Details

Impact

An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users who are permitted to view all tasks.
  • Avoid placing sensitive values in template input parameters until the patched package is deployed.

Timeline

Published
1 hour ago
October 07, 2026 at 05:58 PM UTC
Fixed (4.1.0)
1 month ago
August 28, 2026 at 08:20 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 06:15 PM UTC