GHSA-h53x-hjx6-25grLowCVSS 3.5
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
🔗 CVE IDs covered (1)
📋 Description
Impact
Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
Patches
Patched in @backstage/plugin-kubernetes-backend version 0.21.10
Workarounds
- Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required.
- Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities.
🎯 Affected products1
- npm/@backstage/plugin-kubernetes-backend:< 0.21.10
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-h53x-hjx6-25gr
- https://nvd.nist.gov/vuln/detail/CVE-2026-106487
- https://github.com/backstage/backstage/commit/c14f8be6908f0f719b16356e5492352311e28946
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-h53x-hjx6-25gr