GHSA-gp6m-x9vw-5c5x: Medium severity npm/@backstage/plugin-catalog-backend-module-gitlab vulnerability
Impact
Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.
Patches
- Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.
Workarounds
- Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading. - Enforce organization membership independently at the authenticating proxy or sign-in resolver.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-catalog-backend-module-gitlabto a version that resolves this vulnerability.Fixed in 0.8.7 - Upgrade
Upgrade
@backstage/plugin-catalog-backend-module-gitlabto a version that resolves this vulnerability.Fixed in 0.8.7 - Configuration
Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading.
Backstage GitLab organization ingestion event-driven GitLab organization ingestion = disabled - Compensating control
Enforce organization membership independently at the authenticating proxy or sign-in resolver.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments that enable GitLab organization event ingestion and use scoped catalog users as an access boundary are affected. Exposure depends on the sign-in and permission configuration.
What access could an attacker gain?
An unintended catalog identity may be admitted, potentially giving unauthorized access with the permissions assigned to a standard authenticated user. Exploitation requires the ability to authenticate as a user; the advisory does not indicate anonymous access.
What should be done if upgrading cannot happen immediately?
Disable event-driven GitLab organization ingestion and use scheduled discovery instead. Also enforce organization membership separately through the authenticating proxy or sign-in resolver.
What version contains the fix?
Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.