Missing CSRF protection on several actions

PPSA-202403-2


Summary

Several actions in Private Packagist were not protected against cross-site request forgery (CSRF): granting and revoking All package access for teams, triggering a package update, downloading a package archive, promoting a synchronization to primary, and resending email address confirmations.

Who was affected

All users of Private Packagist Cloud until the fix on March 21, 2024, and of Private Packagist Self-Hosted installations running a version before 2.0.2 (KOTS) or 1.12.4 (Replicated Native).

Impact

A malicious website visited by a user logged in to Private Packagist could have made the user, without their consent, grant or revoke All package access for a team, trigger a package update, download a package archive, promote a synchronization to primary, or resend an email address confirmation. Each action was limited to what the user was allowed to do. Granting All package access had the largest effect: the members of the team gained access to all packages of the organization. The website could not read any responses from Private Packagist, such as the contents of a downloaded archive.

What we did

Granting and revoking All package access, triggering a package update, downloading a package archive, promoting a synchronization to primary, and resending an email address confirmation now require a valid CSRF token.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.2 (KOTS) or 1.12.4 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Sahil Negi for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!