| ID | PPSA-202003-1 |
|---|---|
| Upstream CVE | CVE-2020-10590 in Replicated, a vulnerability in an upstream component used by Private Packagist |
| Published | 2020-03-23 |
| Private Packagist Cloud | Not affected. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.9.9. Fixed in 1.9.9. |
Summary
A security vulnerability in Replicated, the platform Private Packagist Self-Hosted was installed and managed with at the time, exposed sensitive data through an improperly secured API.
Who was affected
Private Packagist Self-Hosted installations running a version before 1.9.9. Private Packagist Cloud does not use Replicated and was not affected.
Impact
An attacker with network access to the Replicated Admin Console port (8800) of a Private Packagist Self-Hosted installation could have downloaded the TLS certificate and private key used by the Admin Console, without logging in. With the private key, an attacker able to intercept network traffic to the Admin Console could have impersonated it, for example to read the Admin Console password when an administrator logged in. Installations that did not expose port 8800 beyond a trusted network were only reachable by attackers inside that network.
What we did
We released Private Packagist Self-Hosted 1.9.9, which resolves the vulnerability, on March 23, 2020.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 1.9.9 or any later version. We recommend upgrading to the latest release.
Start Free Trial
Login to create an organization and start your free trial!