| ID | PPSA-202309-1 |
|---|---|
| Published | 2023-09-01 |
| Private Packagist Cloud | Affected from 2023-08-10. Fixed on 2023-09-01. |
| Private Packagist Self-Hosted (Replicated Native) | Affected = 1.12.0 | = 1.12.0-pl1 | = 1.12.0-pl2. Fixed in 1.12.1. |
Summary
Users who logged in through OAuth with GitHub, GitLab, or Bitbucket were not asked for their multi-factor authentication (MFA) code, even if their organization or their own account required MFA.
Who was affected
Private Packagist Cloud from August 10, 2023 until the fix on September 1, 2023, and Private Packagist Self-Hosted 1.12.0, 1.12.0-pl1, and 1.12.0-pl2. Only logins through OAuth were affected. MFA was required as configured at all times for users logging in with email address and password.
Impact
An attacker who had gained access to a user's account on GitHub, GitLab, or Bitbucket could have logged in to the user's Private Packagist account through OAuth without the second factor that the organization or the user required. The attacker would then have had all of the user's access in Private Packagist. Without access to the user's OAuth provider account, MFA still protected the Private Packagist account.
What we did
We fixed the login flow so that MFA is required after an OAuth login again, and released Private Packagist Self-Hosted 1.12.1 on September 1, 2023.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 1.12.1 or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
Start Free Trial
Login to create an organization and start your free trial!