Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
Patched in @backstage/plugin-kubernetes-backend version 0.21.10
{
"cwe_ids": [
"CWE-441"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:01:08Z",
"nvd_published_at": "2026-10-06T21:17:17Z",
"severity": "LOW"
}