Multi-factor authentication not required after OAuth login

PPSA-202309-1


Summary

Users who logged in through OAuth with GitHub, GitLab, or Bitbucket were not asked for their multi-factor authentication (MFA) code, even if their organization or their own account required MFA.

Who was affected

Private Packagist Cloud from August 10, 2023 until the fix on September 1, 2023, and Private Packagist Self-Hosted 1.12.0, 1.12.0-pl1, and 1.12.0-pl2. Only logins through OAuth were affected. MFA was required as configured at all times for users logging in with email address and password.

Impact

An attacker who had gained access to a user's account on GitHub, GitLab, or Bitbucket could have logged in to the user's Private Packagist account through OAuth without the second factor that the organization or the user required. The attacker would then have had all of the user's access in Private Packagist. Without access to the user's OAuth provider account, MFA still protected the Private Packagist account.

What we did

We fixed the login flow so that MFA is required after an OAuth login again, and released Private Packagist Self-Hosted 1.12.1 on September 1, 2023.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 1.12.1 or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!