CVE-2026-106458
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Summary
Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters. An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This issue is fixed in version 0.5.15.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| backstage | backstage | >= 1.38.0, < 1.55.0 | affected |
| @backstage | plugin-catalog-backend-module-bitbucket-server | >= 0.4.0, < 0.5.15 | affected |
Weaknesses
- CWE-863: CWE-863: Incorrect Authorization
References
- https://github.com/backstage/backstage/security/advisories/GHSA-c36c-cf6r-ghgj
- https://github.com/backstage/backstage/commit/989db63b6f87c8fc04d440f296ad89e10c79b363
- https://github.com/backstage/backstage/releases/tag/v1.55.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.