Repository navigation
fix(deps): update dependency @backstage/plugin-proxy-backend to v0.6.18 [security] - #5629
renovate[bot] wants to merge 1 commit into
Conversation
…18 [security] Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
|
Hi @renovate[bot]. Thanks for your PR. I'm waiting for a redhat-developer member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5629 +/- ##
=======================================
Coverage 72.77% 72.77%
=======================================
Files 68 68
Lines 786 786
Branches 113 113
=======================================
Hits 572 572
Misses 213 213
Partials 1 1
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|



This PR contains the following updates:
0.6.17→0.6.18Backstage: Inconsistent credential enforcement for overlapping proxy routes
CVE-2026-106456 / GHSA-472h-9c5j-prrr
More information
Details
Impact
An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy.
Exploitation requires this specific overlapping route configuration. The resulting confidentiality and integrity impact depends on the capabilities exposed by the nested upstream.
Patches
Upgrade
@backstage/plugin-proxy-backendto version0.6.18or later. The fixed package is available in Backstage v1.55.0.Workarounds
dangerously-allow-unauthenticated.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-proxy-backend)
v0.6.18Compare Source
Patch Changes
736d84e: Use locale-insensitive Unicode casing for consistent string handling across environments.42580a2: Improved request path handling in the proxy-backend.9df9292: Ensure HTTP proxy requests consistently apply their configured credential requirements.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.