Owners team memberships could be managed through the API

PPSA-202403-1


Summary

The team membership API allowed adding members to and removing members from the Owners team. This made it possible for admins to promote themselves to owners.

Who was affected

Organizations on Private Packagist Cloud until the fix on March 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.2 (KOTS) or 1.12.4 (Replicated Native). Only members who could use API credentials with access to team management could make use of this.

Impact

A member with admin access and API credentials with access to team management could have used the API to make themselves or another user an owner of the organization, or to remove owners. A new owner would have gained full control of the organization, including the permissions reserved for owners. A removed owner would have lost them.

What we did

Memberships of the Owners team can no longer be managed through the API.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.2 (KOTS) or 1.12.4 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.
  • Owners who want to make sure the Owners team only contains the expected members can review it on the Teams page and in the audit log.

Credits

Thanks to Anees Khan for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!