CVE-2026-32237

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response payload. Deployments that have configured scaffolder.defaultEnvironment.secrets are affected. This is patched in @backstage/plugin-scaffolder-backend version 3.1.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:backstage\/plugin-scaffolder-backend:*:*:*:*:*:node.js:*:*

History

30 Apr 2026, 18:34

Type Values Removed Values Added
CPE cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage\/plugin-scaffolder-backend:*:*:*:*:*:node.js:*:*
First Time Linuxfoundation backstage\/plugin-scaffolder-backend

19 Mar 2026, 20:49

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linuxfoundation
Linuxfoundation backstage
Summary
  • (es) Backstage es un framework abierto para construir portales de desarrollador. Antes de la versión 3.1.5, los usuarios autenticados con permiso para ejecutar 'dry-runs' de scaffolder pueden obtener acceso a secretos de entorno configurados en el servidor a través de la respuesta de la API del 'dry-run'. Los secretos se redactan correctamente en la salida de registro, pero no en todas las partes de la carga útil de la respuesta. Las implementaciones que han configurado scaffolder.defaultEnvironment.secrets se ven afectadas. Esto se ha parcheado en la versión 3.1.5 de @backstage/plugin-scaffolder-backend.
CPE cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
References () https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209f98dfce - () https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209f98dfce - Patch
References () https://github.com/backstage/backstage/security/advisories/GHSA-8wq8-6859-qx77 - () https://github.com/backstage/backstage/security/advisories/GHSA-8wq8-6859-qx77 - Vendor Advisory

12 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 19:16

Updated : 2026-04-30 18:34


NVD link : CVE-2026-32237

Mitre link : CVE-2026-32237

CVE.ORG link : CVE-2026-32237


JSON object : View

Products Affected

linuxfoundation

  • backstage\/plugin-scaffolder-backend
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo