Backstage 是一个用于构建开发者门户的开放框架。在版本 0.21.9 之前,@backstage/plugin-kubernetes-backend 插件在 Kubernetes 资源查询中存在敏感信息泄露漏洞。拥有标准 Kubernetes 资源读取权限的已认证用户,可以获取到 Kubernetes 插件本应遮蔽的敏感值,从而可能泄露连接集群中存储的凭证和其他机密信息。泄露范围仅限于 Backstage 服务账号有权读取且匹配目标目录实体的命名空间和标签选择器的资源。如果部署的集群凭据未授予对这些资源的读
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.54.2 | - |
|
| @backstage | plugin-kubernetes-backend | < 0.21.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106510 | 7.7 HIGH | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106560 | 7.1 HIGH | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-106559 | 6.3 MEDIUM | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106562 | 4.3 MEDIUM | Backstage: Incorrect authorization in search engine permission filtering |
No comments yet