| ID | PPSA-202104-1 |
|---|---|
| Upstream CVE | CVE-2021-29472 in Composer (pkg:composer/composer/composer), a vulnerability in an upstream component used by Private Packagist |
| Published | 2021-04-27 |
| Private Packagist Cloud | Affected. Fixed on 2021-04-22. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.10.6. Fixed in 1.10.6. |
Summary
A command injection vulnerability in Composer, which Private Packagist uses to read and process packages, could have allowed logged in users or maintainers of third-party packages to run shell commands on the servers that process package updates. Repository URLs and package source URLs starting with -- were not rejected, and Composer passed them to Mercurial as command line options.
Who was affected
Private Packagist Cloud until the fix on April 22, 2021, and Private Packagist Self-Hosted installations running a version before 1.10.6. On Self-Hosted, the affected component is the background worker that processes package updates.
Impact
An attacker able to enter a repository URL when adding a package, or to provide package information with a crafted source URL, could have run arbitrary shell commands on the servers that process package updates. The servers that process package updates have access to the code of the packages they process and to the credentials Private Packagist uses to fetch them. An attacker could therefore have accessed the code and credentials of the packages processed on these servers.
What we did
We deployed the fix to Private Packagist Cloud within 12 hours of receiving the report on April 22, 2021, before the vulnerability was published, and released Private Packagist Self-Hosted 1.10.6 on April 27, 2021. Self-Hosted 1.10.7 added further validation, so that package information that could exploit outdated Composer clients is no longer delivered to them.
To the best of our knowledge, this vulnerability was not exploited on Private Packagist Cloud. We reviewed our logs and audited the database contents of Private Packagist Cloud, and found no sign that the vulnerability was exploited.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 1.10.6 or any later version. We recommend upgrading to the latest release. Afterwards, run
replicated admin audit --vulnerability=CVE-2021-29472to check for package information or processed jobs attempting to exploit this vulnerability. If it reports any, contact us at contact@packagist.com. - Private Packagist Cloud: No action is required.
- We recommend that everyone keeps the Composer version they use up to date, as described in the Composer announcement, and checks that the URLs in their composer.lock files do not start with
--, which could be interpreted as command line options.
Start Free Trial
Login to create an organization and start your free trial!