Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8wq8-6859-qx77 | @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint |
Thu, 30 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation backstage\/plugin-scaffolder-backend
|
|
| CPEs | cpe:2.3:a:linuxfoundation:backstage\/plugin-scaffolder-backend:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Linuxfoundation backstage
|
Linuxfoundation backstage\/plugin-scaffolder-backend
|
Thu, 19 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation backstage |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation backstage |
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backstage
Backstage plugin-scaffolder-backend |
|
| Vendors & Products |
Backstage
Backstage plugin-scaffolder-backend |
Fri, 13 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 12 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response payload. Deployments that have configured scaffolder.defaultEnvironment.secrets are affected. This is patched in @backstage/plugin-scaffolder-backend version 3.1.5. | |
| Title | @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-12T20:46:35.503Z
Reserved: 2026-03-11T14:47:05.684Z
Link: CVE-2026-32237
Updated: 2026-03-12T20:38:12.324Z
Status : Analyzed
Published: 2026-03-12T19:16:19.040
Modified: 2026-04-30T18:34:38.280
Link: CVE-2026-32237
OpenCVE Enrichment
Updated: 2026-03-23T09:55:00Z
Github GHSA