GHSA-h53x-hjx6-25gr: Low severity npm/@backstage/plugin-kubernetes-backend vulnerability
Impact
Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
Patches
Patched in @backstage/plugin-kubernetes-backend version 0.21.10
Workarounds
- Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required. - Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.10 - Upgrade
Upgrade
@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.10 - Configuration
Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required.
Backstage Kubernetes backend service account authentication configuration = static configuration - Compensating control
Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities, including kubernetes-cluster Resource entities.