content: The names of private packages were accidentally exposed for a little over a week. The flaw has been found and fixed.
content: The names of private packages were accidentally exposed for a little over a week. The flaw has been found and fixed.
> We determined that this vulnerability was due to inconsistent authorization checks and validation of data across several microservices that handle requests to the npm registry. In this architecture, the authorization service was properly validating user authorization to packages based on data passed in request URL paths. However, the service that performs underlying updates to the registry data determined which package to publish based on the contents of the uploaded package file.
The main article title is such corpspeak that it would go against the site guidelines to use it—that sort of corporate press release title is typically misleading, linkbait, or both.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...
This is not “security issues”.
It was possible, for years, for anyone to upload anything for any package.
For a package manager, this is THE security issue, all caps.
Commitment to security = security was broken. It's similar to "we value your privacy" and or "announcements about the future of the project". Finest newspeak.