Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c36c-cf6r-ghgj | Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters. An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This issue is fixed in version 0.5.15. | |
| Title | Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:07:16.596Z
Reserved: 2026-10-06T16:49:40.591Z
Link: CVE-2026-106458
Updated: 2026-10-07T15:27:15.864Z
Status : Awaiting Analysis
Published: 2026-10-06T21:17:16.270
Modified: 2026-10-07T17:16:48.263
Link: CVE-2026-106458
No data.
OpenCVE Enrichment
Updated: 2026-10-07T00:15:07Z
Github GHSA