GHSA-238x-w2j9-gwwr: Npm/payload vulnerability
Impact
Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.
You are affected if:
- An authentication collection enables useAPIKey. - Users have read access to other user documents containing active API keys.
Patches
Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Configuration
Disable useAPIKey or restrict users to reading only their own authentication document.
Authentication collection useAPIKey and authentication document read access = Disable useAPIKey, or restrict users to reading only their own authentication document - Operational
Rotate any API key that may have been exposed.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments have an authentication collection with useAPIKey enabled and allow users to read other users' documents that contain active API keys. Both conditions are required.
What access does an attacker need to exploit this?
The attacker needs read access to another user's authentication document containing an active API key. A retrieved key provides the permissions of the account that owns it until it is rotated or disabled.
What can be done if an upgrade cannot be applied immediately?
Disable useAPIKey, or restrict users so they can read only their own authentication document. Rotate any API keys that may already have been exposed.
How can we determine whether API keys may have been exposed?
Review whether users could read other users' authentication documents while useAPIKey was enabled, and identify documents with active API keys. Any keys in documents accessible to other users should be treated as potentially exposed and rotated.
Which package versions contain the fix?
Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.