Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-32791 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed in the permission backend. If the permission system is not in use or if the installed permission policy does not use conditional decisions, there is no impact. This issue has been patched in version 0.6.0 of the permissions backend. A workaround includes having administrators of the permission policies ensure that they are crafted in such a way that conditional decisions do not contain any sensitive information.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-213Exposure of Sensitive Information Due to Incompatible Policies[email protected]

Affected Products

ProductVersions
Backstage
< 0.6.0 (semver)

CPE

  • cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 0.6.0moderate effort
  • Mitigation:low effort

    Administrators of the permission policies can ensure that they are crafted in such a way that conditional decisions do not contain any sensitive information.

@backstage/plugin-permission-backend
All versions

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-32791
NVD Published Date:
Apr 16, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]