Linuxfoundation
Linuxfoundation Backstage: vulnerabilidades y CVE
Linuxfoundation Backstage tiene 14 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73666 | Alta (8.2) | 0.68% | — | 13 ago 2026 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and… |
| CVE-2026-73563 | Media (4.7) | 0.28% | — | 13 ago 2026 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string… |
| CVE-2026-32236 | Baja (1.7) | 0.47% | — | 12 mar 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when… |
| CVE-2026-32235 | Media (4.7) | 0.23% | — | 12 mar 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have… |
| CVE-2026-25153 | Alta (8.8) | 0.61% | — | 30 ene 2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11… |
| CVE-2026-25152 | Media (6.5) | 0.44% | — | 30 ene 2026 | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11… |
| CVE-2024-46976 | Media (5.4) | 0.29% | — | 17 sept 2024 | Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed… |
| CVE-2024-45816 | Media (6.5) | 0.73% | — | 17 sept 2024 | Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the… |
| CVE-2024-45815 | Media (6.5) | 0.51% | — | 17 sept 2024 | Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a… |
| CVE-2023-6944 | Media (5.7) | 0.56% | — | 4 ene 2024 | A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The… |
| CVE-2023-35926 | Crítica (9.9) | 1.9% | — | 22 jun 2023 | Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this… |
| CVE-2021-43783 | Alta (8.5) | 1.2% | — | 29 nov 2021 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the… |
| CVE-2021-41151 | Media (4.9) | 1.3% | — | 18 oct 2021 | Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a… |
| CVE-2021-32662 | Media (6.5) | 1.3% | — | 3 jun 2021 | Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor… |