Security News > 2021 > August > PyPI Python Package Repository Patches Critical Supply Chain Flaw

PyPI Python Package Repository Patches Critical Supply Chain Flaw
2021-08-02 03:50

The maintainers of Python Package Index last week issued fixes for three vulnerabilities, one among which could be abused to achieve arbitrary code execution and take full control of the official third-party software repository.

The security weaknesses were discovered and reported by Japanese security researcher RyotaK, who in the past has disclosed critical vulnerabilities in the Homebrew Cask repository and Cloudflare's CDNJS library.

Vulnerability in Role Deletion on PyPI - An exploitable vulnerability in the mechanisms for deleting roles on PyPI was discovered by a security researcher, which would allow an attacker to remove roles for projects not under their control.

Vulnerability in GitHub Actions workflow for PyPI - An exploitable vulnerability in a GitHub Actions workflow for PyPI's source repository could allow an attacker to obtain write permissions against the pypa/warehouse repository.

A more critical flaw concerns an issue in the GitHub Actions workflow for PyPI's source repository named "Combine-prs.yml," resulting in a scenario wherein an adversary could obtain write permission for the main branch of the "Pypa/warehouse" repository, and in the process execute malicious code on pypi.org.

"As I've mentioned several times before, some supply chains have critical vulnerabilities. However, a limited number of people are researching supply chain attacks, and most supply chains are not properly protected. Therefore, I believe that it's necessary for users who depend on the supply chain to actively contribute to improving security in the supply chain."


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/xPmhYci7K18/pypi-python-package-repository-patches.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Python 27 10 87 73 27 197
Pypi 14 0 0 14 0 14