logo

Database

Improper authorization control for web services In @backstage/plugin-search-backend

Description

Backstage has incorrect authorization in search engine permission filtering

Impact

An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.

Patches

    Upgrade @backstage/plugin-search-backend to 2.1.6

    Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7

Workarounds

If you are unable to upgrade immediately:

    Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types

    Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions