| ID | PPSA-202406-2 |
|---|---|
| Published | 2024-06-12 |
| Private Packagist Cloud | Affected. Fixed on 2024-06-12. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.3. Fixed in 2.0.3. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.12.5. Fixed in 1.12.5. |
Summary
The link to join a team could be modified to send the user to an arbitrary external website after following it.
Who was affected
Users of Private Packagist Cloud until the fix on June 12, 2024, and of Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). An attacker had to send the modified link to the user through another channel, for example by email.
Impact
An attacker could have sent users a modified link to join a team that starts with a Private Packagist address but sent the user to a website controlled by the attacker after following it, for example to make a phishing page look trustworthy. The link itself gave the attacker no access to Private Packagist.
What we did
The link to join a team now only redirects to pages of Private Packagist.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
Credits
Thanks to Julian Hector for reporting this issue.
Start Free Trial
Login to create an organization and start your free trial!