| ID | PPSA-202406-4 |
|---|---|
| Published | 2024-06-12 |
| Private Packagist Cloud | Affected. Fixed on 2024-06-12. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.3. Fixed in 2.0.3. |
| Private Packagist Self-Hosted (Replicated Native) | Affected < 1.12.5. Fixed in 1.12.5. |
Summary
The version field of the form to create a custom package was vulnerable to reflected cross-site scripting (XSS).
Who was affected
Organizations on Private Packagist Cloud until the fix on June 12, 2024, and on Private Packagist Self-Hosted installations running a version before 2.0.3 (KOTS) or 1.12.5 (Replicated Native). Only users allowed to add packages could submit the form.
Impact
Script code submitted in the version field of the form to create a custom package could have run in the browser of the user who submitted the form, with that user's access to Private Packagist, for example to read data or perform actions in the organization as that user.
What we did
The value of the version field in the custom package form is now always shown as plain text.
Do customers need to do anything
- Private Packagist Self-Hosted: Upgrade to 2.0.3 (KOTS) or 1.12.5 (Replicated Native) or any later version. We recommend upgrading to the latest release.
- Private Packagist Cloud: No action is required.
Credits
Thanks to Maciej Piechota (haqpl) for reporting this issue.
Start Free Trial
Login to create an organization and start your free trial!