Sensitive data exposed through a Replicated API

PPSA-202003-1


Summary

A security vulnerability in Replicated, the platform Private Packagist Self-Hosted was installed and managed with at the time, exposed sensitive data through an improperly secured API.

Who was affected

Private Packagist Self-Hosted installations running a version before 1.9.9. Private Packagist Cloud does not use Replicated and was not affected.

Impact

An attacker with network access to the Replicated Admin Console port (8800) of a Private Packagist Self-Hosted installation could have downloaded the TLS certificate and private key used by the Admin Console, without logging in. With the private key, an attacker able to intercept network traffic to the Admin Console could have impersonated it, for example to read the Admin Console password when an administrator logged in. Installations that did not expose port 8800 beyond a trusted network were only reachable by attackers inside that network.

What we did

We released Private Packagist Self-Hosted 1.9.9, which resolves the vulnerability, on March 23, 2020.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 1.9.9 or any later version. We recommend upgrading to the latest release.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!