| ID | PPSA-202204-1 |
|---|---|
| Upstream CVE | CVE-2022-24828 in Composer (pkg:composer/composer/composer), a vulnerability in an upstream component used by Private Packagist |
| Published | 2022-04-13 |
| Private Packagist Cloud | Affected. Fixed on 2022-04-08. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.11.3. Fixed in 1.11.3. |
Summary
An argument injection vulnerability in Composer, which Private Packagist uses to read and process packages, could have allowed maintainers of private packages to run shell commands and create files on the servers that process package updates. Composer passed the readme field of the composer.json file in the default branch of a Mercurial repository, and the name of the default branch of a git repository, to Mercurial and git without rejecting values that start with a dash, so they could be interpreted as command line options.
Who was affected
Private Packagist Cloud until the fix on April 8, 2022, and Private Packagist Self-Hosted installations running a version before 1.11.3. Exploiting the issue required the ability to change a Mercurial or git repository that is added to Private Packagist as a package. Installing packages from Private Packagist with Composer was not affected, including with --prefer-source.
Impact
A malicious maintainer of a private package, able to change a Mercurial or git repository added to Private Packagist, could have run shell commands or created files on the servers that process package updates. The servers that process package updates have access to the code of the packages they process and to the credentials Private Packagist uses to fetch them. An attacker could therefore have accessed the code and credentials of the packages processed on these servers.
What we did
We deployed the fix to Private Packagist Cloud within 24 hours of receiving the report on April 7, 2022, before the vulnerability was published, and released Private Packagist Self-Hosted 1.11.3 on April 13, 2022.
To the best of our knowledge, this vulnerability was not exploited on Private Packagist Cloud. We reviewed our logs and audited the database contents of Private Packagist Cloud, and found no sign that the vulnerability was exploited.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 1.11.3 or any later version. We recommend upgrading to the latest release. Afterwards, run
replicated admin audit --vulnerability=CVE-2022-24828to check for package information or files attempting to exploit this vulnerability. If it reports any, contact us at contact@packagist.com. - Private Packagist Cloud: No action is required.
- We recommend that everyone keeps the Composer version they use up to date, as described in the Composer advisory.
Start Free Trial
Login to create an organization and start your free trial!