| ID | PPSA-202406-3 |
|---|---|
| Published | 2024-06-12 |
| Private Packagist Cloud | Affected. Fixed on 2024-06-12. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.3. Fixed in 2.0.3. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.12.5. Fixed in 1.12.5. |
Summary
The base URL field of the form to add or edit an integration in the organization settings was vulnerable to reflected cross-site scripting (XSS).
Who was affected
Organizations on Private Packagist Cloud until the fix on June 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). Only users with access to the integration settings could submit the form.
Impact
Script code submitted in the base URL field of the form to add or edit an integration could have run in the browser of the user who submitted the form, with that user's access to Private Packagist, for example to read data or perform actions in the organization as that user.
What we did
The value of the base URL field in the integration form is now always shown as plain text.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
Credits
Thanks to Maciej Piechota (haqpl) for reporting this issue.
Start Free Trial
Login to create an organization and start your free trial!