GHSA-9325-vq29-gp3v: Medium severity npm/@backstage/plugin-search-backend-module-elasticsearch vulnerability
Impact
An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.
Patches
- Upgrade @backstage/plugin-search-backend to 2.1.6 - Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7
Workarounds
If you are unable to upgrade immediately:
- Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types - Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-search-backend-module-elasticsearchto a version that resolves this vulnerability.Fixed in 1.8.7 - Upgrade
Upgrade
npm/@backstage/plugin-search-backendto a version that resolves this vulnerability.Fixed in 2.1.6 - Upgrade
Upgrade
@backstage/plugin-search-backend-module-elasticsearchto a version that resolves this vulnerability.Fixed in 1.8.7 - Upgrade
Upgrade
@backstage/plugin-search-backendto a version that resolves this vulnerability.Fixed in 2.1.6 - Configuration
Temporarily use CONDITIONAL decisions with per-result filtering instead of blanket DENY for search document types.
Backstage permission policies for search document types permission decision = CONDITIONAL - Compensating control
Restrict Elasticsearch/OpenSearch index access at the cluster level so the search service account can only reach expected Backstage indices.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments have Backstage permissions enabled with permission.enabled: true and use Elasticsearch or OpenSearch as the search backend. The issue specifically concerns users who are subject to a DENY policy for search document types.
What access does an attacker need?
An attacker needs to be an authenticated Backstage user. No user interaction is required, but the user must be subject to a DENY policy for the relevant search document types.
How can exposure be reduced before upgrading?
Change applicable permission policies from blanket DENY decisions to CONDITIONAL decisions that perform per-result filtering. Also restrict Elasticsearch or OpenSearch cluster access so the search service account can access only the intended Backstage indices.
Which package versions contain the fixes?
Upgrade @backstage/plugin-search-backend to version 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch to version 1.8.7.