| ID | PPSA-202403-1 |
|---|---|
| Published | 2024-03-12 |
| Private Packagist Cloud | Affected. Fixed on 2024-03-12. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.2. Fixed in 2.0.2. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.12.4. Fixed in 1.12.4. |
Summary
The team membership API allowed adding members to and removing members from the Owners team. This made it possible for admins to promote themselves to owners.
Who was affected
Organizations on Private Packagist Cloud until the fix on March 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.2 (KOTS) or 1.12.4 (Replicated Native). Only members who could use API credentials with access to team management could make use of this.
Impact
A member with admin access and API credentials with access to team management could have used the API to make themselves or another user an owner of the organization, or to remove owners. A new owner would have gained full control of the organization, including the permissions reserved for owners. A removed owner would have lost them.
What we did
Memberships of the Owners team can no longer be managed through the API.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.2 (KOTS) or 1.12.4 (Replicated Native) or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
- Owners who want to make sure the Owners team only contains the expected members can review it on the Teams page and in the audit log.
Credits
Thanks to Anees Khan for reporting this issue.
Start Free Trial
Login to create an organization and start your free trial!