GHSA-f7hx-52q9-hcrf: Critical severity npm/payload vulnerability
Impact
An attacker can submit a request to a specific endpoint that permits collection documents to be updated regardless of access control and field level access control.
You are affected if:
- You are configuring orderable: true with any collection or join field.
Patches
In the patched version access control is properly enforced.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34