Reflected cross-site scripting in the integration form

PPSA-202406-3


Summary

The base URL field of the form to add or edit an integration in the organization settings was vulnerable to reflected cross-site scripting (XSS).

Who was affected

Organizations on Private Packagist Cloud until the fix on June 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). Only users with access to the integration settings could submit the form.

Impact

Script code submitted in the base URL field of the form to add or edit an integration could have run in the browser of the user who submitted the form, with that user's access to Private Packagist, for example to read data or perform actions in the organization as that user.

What we did

The value of the base URL field in the integration form is now always shown as plain text.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Maciej Piechota (haqpl) for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!