Intel

AIKIDO-2025-10259

@backstage/plugin-permission-backend is vulnerable to Exposure of Sensitive Information Due to Incompatible Policies

Exposure of Sensitive Information Due to Incompatible PoliciesCVE-2025-32791 Published Apr 22, 2025

49

Medium Risk

This Affects:

JS@backstage/plugin-permission-backend
0.1.0 - 0.5.55
Fixed in 0.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of the @backstage/plugin-permission-backend library are vulnerable to information exposure due to insufficient protection of conditional decision data stored in policies. An unauthorized user can infer or extract sensitive details about conditional logic or access decisions they should not be permitted to view.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@backstage/plugin-permission-backend is vulnerable to Exposure of Sensitive Information Due to Incompatible Policies in versions 0.1.0 - 0.5.55.

How to fix this

Upgrade the @backstage/plugin-permission-backend library to the patch version.