GHSA-f8j4-p5cr-p777

Suggest an improvement
Source
https://github.com/advisories/GHSA-f8j4-p5cr-p777
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-f8j4-p5cr-p777/GHSA-f8j4-p5cr-p777.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f8j4-p5cr-p777
Aliases
  • CVE-2025-32791
Published
2025-04-16T15:34:21Z
Modified
2025-04-17T12:39:25Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Permission policy information leakage in Backstage permission system
Details

Impact

A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed in the permission backend. If the permission system is not in use or if the installed permission policy does not use conditional decisions, there is no impact.

Patches

This issue has been resolved in version 0.6.0 of the permissions backend.

Workarounds

Administrators of the permission policies can ensure that they are crafted in such a way that conditional decisions do not contain any sensitive information.

References

If you have any questions or comments about this advisory:

Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README

Database specific
{
    "severity": "MODERATE",
    "nvd_published_at": "2025-04-16T22:15:14Z",
    "github_reviewed_at": "2025-04-16T15:34:21Z",
    "cwe_ids": [
        "CWE-213"
    ],
    "github_reviewed": true
}
References

Affected packages

npm / @backstage/plugin-permission-backend

Package

Name
@backstage/plugin-permission-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-permission-backend

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0