Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability until you can update to RHDH 1.1, ensure that the base64 encoded GitLab token does not contain a newline character at the end. Removing the newline from the token prevents the unintended disclosure of the access token through the frontend.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0292 | @backstage/backend-app-api leaks GitLab access tokens |
Github GHSA |
GHSA-86rg-pf4c-5grg | @backstage/backend-app-api leaks GitLab access tokens |
Fri, 05 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhdh:1.1::el9 | |
| References |
|
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T18:07:14.520Z
Reserved: 2023-12-19T10:23:24.260Z
Link: CVE-2023-6944
Updated: 2024-08-02T08:42:08.676Z
Status : Modified
Published: 2024-01-04T10:15:11.517
Modified: 2025-09-05T12:15:31.357
Link: CVE-2023-6944
OpenCVE Enrichment
No data.
EUVD
Github GHSA