Open redirect in the link to join a team

PPSA-202406-2


Summary

The link to join a team could be modified to send the user to an arbitrary external website after following it.

Who was affected

Users of Private Packagist Cloud until the fix on June 12, 2024, and of Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). An attacker had to send the modified link to the user through another channel, for example by email.

Impact

An attacker could have sent users a modified link to join a team that starts with a Private Packagist address but sent the user to a website controlled by the attacker after following it, for example to make a phishing page look trustworthy. The link itself gave the attacker no access to Private Packagist.

What we did

The link to join a team now only redirects to pages of Private Packagist.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Julian Hector for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!