Packages of another organization could be imported

PPSA-202405-1


Summary

Under specific conditions, an attacker could have imported a package of another organization into their own organization.

Who was affected

Organizations with packages created with the "git" type on Private Packagist Cloud until the fix on May 29, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). On Self-Hosted, the attacker would have needed an account on the same installation. The attacker also needed to know the package's full source URL, details of how files are stored on the Private Packagist servers, and the internal identifier of the targeted organization.

Impact

An attacker with an account on Private Packagist could have imported a package of another organization into their own organization and read its code. This required that the package was created with the "git" type and that the attacker knew the package's full source URL, details of how files are stored on the Private Packagist servers, and the internal identifier of the other organization. On Self-Hosted, the attacker needed an account on the same installation.

What we did

Private Packagist no longer accepts package sources that point to files stored on its own servers. To the best of our knowledge after reviewing logs and audit records as far back as we have them, this issue was not exploited before it was discovered.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Maciej Piechota (haqpl) for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!