GHSA-7c34-32v3-j575: Npm/payload vulnerability
Impact
A readable collection could expose information about protected documents in a related collection.
You are affected if:
- You expose a readable collection with a relationship to a collection protected by access.read where constraints.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Upgrade Payload packages >= 3.90.0 or >= 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments are affected when they expose a readable collection that has a relationship to another collection protected by access.read constraints.
What should be done to remediate this issue?
Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.
Is there a workaround if an upgrade cannot be performed immediately?
No complete workaround is available. Upgrading the Payload packages is the stated remediation.