Skip to content

fix(deps): update dependency @backstage/plugin-auth-backend to v0.27.1 [security]#4404

Merged
openshift-merge-bot[bot] merged 1 commit intomainfrom
renovate/npm-backstage-plugin-auth-backend-vulnerability
Mar 25, 2026
Merged

fix(deps): update dependency @backstage/plugin-auth-backend to v0.27.1 [security]#4404
openshift-merge-bot[bot] merged 1 commit intomainfrom
renovate/npm-backstage-plugin-auth-backend-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 13, 2026

This PR contains the following updates:

Package Change Age Confidence
@backstage/plugin-auth-backend (source) 0.27.00.27.1 age confidence

GitHub Vulnerability Alerts

CVE-2026-32235

Impact

The experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured allowedRedirectUriPatterns are affected.

A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.

This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.

Patches

Upgrade to @backstage/plugin-auth-backend version 0.27.1 or later.

Workarounds

Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.

References


Release Notes

backstage/backstage (@​backstage/plugin-auth-backend)

v0.27.1

Compare Source

Patch Changes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Mar 13, 2026

Hi @renovate[bot]. Thanks for your PR.

I'm waiting for a redhat-developer member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 57e76b1 to 7ee1c25 Compare March 13, 2026 21:08
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 7ee1c25 to dac1c4d Compare March 16, 2026 04:07
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from dac1c4d to de50017 Compare March 16, 2026 10:51
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from de50017 to 9f1fd2a Compare March 16, 2026 17:08
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 9f1fd2a to d9d516a Compare March 17, 2026 17:03
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from d9d516a to 9a947af Compare March 18, 2026 05:38
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 9a947af to 88452e6 Compare March 18, 2026 15:23
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 88452e6 to 0b223f9 Compare March 18, 2026 19:04
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 0b223f9 to 0422f21 Compare March 19, 2026 12:17
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 0422f21 to ac2854a Compare March 20, 2026 12:49
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from ac2854a to 1797a14 Compare March 20, 2026 22:50
@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from bbf1b78 to af068f1 Compare March 23, 2026 15:30
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch 2 times, most recently from 4a9256b to 27d7078 Compare March 23, 2026 20:46
@github-actions
Copy link
Copy Markdown
Contributor

The container image build workflow finished with status: cancelled.

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 27d7078 to d6b80d7 Compare March 23, 2026 21:51
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from d6b80d7 to 9317a2e Compare March 24, 2026 11:07
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 9317a2e to 6d3c64a Compare March 24, 2026 16:52
@github-actions
Copy link
Copy Markdown
Contributor

The container image build workflow finished with status: failure.

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 6d3c64a to 099ea61 Compare March 25, 2026 10:18
@github-actions
Copy link
Copy Markdown
Contributor

The container image build workflow finished with status: failure.

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 099ea61 to 83bc0dd Compare March 25, 2026 16:28
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 83bc0dd to 695cf63 Compare March 25, 2026 18:18
…1 [security]

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/npm-backstage-plugin-auth-backend-vulnerability branch from 695cf63 to fd114f5 Compare March 25, 2026 18:23
@sonarqubecloud
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown
Contributor

The container image build workflow finished with status: cancelled.

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

Copy link
Copy Markdown
Member

@kim-tsao kim-tsao left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@kim-tsao
Copy link
Copy Markdown
Member

/ok-to-test

@openshift-merge-bot openshift-merge-bot bot merged commit c527638 into main Mar 25, 2026
17 of 18 checks passed
@openshift-merge-bot openshift-merge-bot bot deleted the renovate/npm-backstage-plugin-auth-backend-vulnerability branch March 25, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant