Impact
Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.
Patches
- Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.
Workarounds
- Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading. - Enforce organization membership independently at the authenticating proxy or sign-in resolver.