Reflected cross-site scripting in the custom package form

PPSA-202406-4


Summary

The version field of the form to create a custom package was vulnerable to reflected cross-site scripting (XSS).

Who was affected

Organizations on Private Packagist Cloud until the fix on June 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). Only users allowed to add packages could submit the form.

Impact

Script code submitted in the version field of the form to create a custom package could have run in the browser of the user who submitted the form, with that user's access to Private Packagist, for example to read data or perform actions in the organization as that user.

What we did

The value of the version field in the custom package form is now always shown as plain text.

Do customers need to do anything

  • Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
  • Private Packagist Cloud: No action is required.

Credits

Thanks to Maciej Piechota (haqpl) for reporting this issue.

All security advisories

Start Free Trial

Login to create an organization and start your free trial!