Vulnerability GHSA-h53x-hjx6-25gr
Low Risk
LOW RISK
CVSS Score: 3.5
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 hours ago
October 07, 2026 at 06:01 PM UTC
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
0.0.0-nightly-20201012104 - 0.21.10-next.0
0.0.0-nightly-20201012104 - 0.21.10-next.0
Summary
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
Details
Impact
Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
Patches
Patched in @backstage/plugin-kubernetes-backend version 0.21.10
Workarounds
- Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required.
- Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities.
Impacted packages
Timeline
Published
3 hours ago
October 07, 2026 at 06:01 PM UTC
Fixed (0.21.10)
1 month ago
August 28, 2026 at 08:19 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC