Missing CSRF protection when disconnecting OAuth accounts

PPSA-202402-1


Summary

Disconnecting a Private Packagist user account from a connected GitHub, GitLab, or Bitbucket account was not protected against cross-site request forgery (CSRF).

Who was affected

All users of Private Packagist Cloud until the fix on February 27, 2024, and of Private Packagist Self-Hosted installations running a version before 2.0.2 (KOTS) or 1.12.4 (Replicated Native).

Impact

A malicious website visited by a user logged in to Private Packagist could have disconnected the user's Private Packagist account from their connected GitHub, GitLab, or Bitbucket accounts without their consent. The user could then no longer log in through OAuth with a disconnected account until they connected it again. The website could not read any data from Private Packagist.

What we did

Disconnecting an OAuth account now requires a valid CSRF token.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.2 (KOTS) or 1.12.4 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Anees Khan for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!