Database/Control plane, storage & DevOps
Backstage Kubernetes backend: resource queries return values the plugin is meant to mask
Impact
Any Backstage user holding the ordinary Kubernetes resource read permission can retrieve values the plugin is designed to redact, so credentials and other confidential material held in the connected clusters come back in plain form. On a GPU fleet Backstage is usually wired to every cluster at once with a single service account, so one portal login becomes a read across the clusters that account can reach rather than across one team's namespace. Exposure is bounded by what the Backstage service account is permitted to read and by the targeted catalog entity's namespace and label selector, so deployments whose cluster credentials do not grant read access to Secrets and similar objects are unaffected. The practical risk is that leaked cluster credentials or registry pull secrets are reusable against the fleet long after the portal session ends.
Who can reach it
Authenticated Backstage user with the standard Kubernetes resource read permission, over the network. No cluster access of their own is required - the plugin uses the Backstage service account's credentials.
What to do
Upgrade @backstage/plugin-kubernetes-backend to 0.21.9 (Backstage release 1.54.2) and restart the Backstage backend; no node or cluster disruption is involved. Because the exposure is read-only disclosure of material the portal already held, also narrow the Backstage service account's RBAC to the object kinds the portal actually needs and rotate any cluster credentials or secrets that were readable through the affected path.
References
Related entries
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSCVE-2022-21417 · MySQL ServerMedium
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverCVE-2023-22084 · MySQL ServerMedium
- RabbitMQ: HTTP API enforces no request body limitCVE-2023-46118 · RabbitMQMedium
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passCVE-2024-23444 · ElasticsearchMedium
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementCVE-2022-49781 · Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttlingMedium
- Intel Neural Compressor (TOCTOU): A time-of-check/time-of-use race in Neural Compressor lets an authenticated localCVE-2024-21792 · Intel Neural Compressor (TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.