GHSA-h53x-hjx6-25grLowCVSS 3.5

Backstage: Unsupported catalog cluster authentication mode in kubernetes backend

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.

Patches

Patched in @backstage/plugin-kubernetes-backend version 0.21.10

Workarounds

  • Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required.
  • Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities.

🎯 Affected products1

  • npm/@backstage/plugin-kubernetes-backend:< 0.21.10

🔗 References (5)