Improper authorization control for web services In @backstage/plugin-search-backend
Description
Backstage has incorrect authorization in search engine permission filtering
Impact
An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.
Patches
Upgrade @backstage/plugin-search-backend to 2.1.6
Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7
Workarounds
If you are unable to upgrade immediately:
Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types
Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 2.1.6 | ||
npm | 1.8.7 |
Aliases
References