PT-2026-22108 · Packistry · Packistry
Maantje
·
Publicado
2026-02-26
·
Atualizado
2026-02-26
·
CVE-2026-27968
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Packistry versions prior to 0.13.0
Description
Packistry is a self-hosted Composer repository for PHP package distribution. Prior to version 0.13.0, the
RepositoryAwareController::authorize() function did not enforce token expiration, allowing expired deploy tokens with the correct ability to access repository endpoints, such as Composer metadata and download APIs. The fix in version 0.13.0 adds an explicit expiration check to the authorize() function, and tests now verify that expired deploy tokens are rejected.Recommendations
Update to version 0.13.0 or later.
Exploit
Correção
Insufficient Session Expiration
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Packistry