GHSA-cq7v-rfgc-5c7v: High severity npm/@backstage/backend-defaults vulnerability
Impact
An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.
Patches
Patched in @backstage/backend-defaults version 0.17.8
Workarounds
If you're unable to upgrade immediately:
- If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Configuration
If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers.
credential access restrictions = separate, purpose-specific unrestricted credentials scoped to trusted consumers - Compensating control
Restrict network-level access to Backstage backend API endpoints to trusted callers only.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Backstage backend deployments using @backstage/backend-defaults with external service credentials that have access restrictions, such as read-only permissions, are exposed if those credentials can reach plugin delegation paths.
What does an attacker need to exploit it?
An attacker needs a restricted external service credential and network access to the relevant Backstage backend API endpoints. No user interaction is required.
How can this be remediated?
Upgrade @backstage/backend-defaults to version 0.17.8 or later.
What can be done if upgrading is not immediately possible?
Replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers where practical. Restrict network-level access to Backstage backend API endpoints so that only trusted callers can reach them.