GHSA-fpww-c55p-cjv6: Infoleak
Impact
A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.
You are affected if:
- You use an affected Payload version. - Users can query a collection with a polymorphic join to sensitive fields.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Configuration
Restrict read access to sensitive collections to reduce exposure.
Sensitive collections read access = restricted
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who has query access can exploit the issue when they can query a collection that has a polymorphic join to sensitive fields. The impact is inference of hidden or read-restricted values, including password-reset tokens.
Are deployments protected by default?
The issue requires both an affected Payload version and users with query access to a collection whose polymorphic join reaches sensitive fields. Deployments without that query path are not described as affected by the advisory.
What should be done if an upgrade cannot happen immediately?
There is no complete workaround. Restrict read access to sensitive collections to reduce exposure, but upgrade Payload packages to version 3.90.0 or later, or 4.0.0-canary.34 or later, as soon as possible.
How can we assess whether our deployment is exposed?
Check whether you use an affected Payload version and whether users can query collections with polymorphic joins to sensitive fields. Pay particular attention to fields whose values are hidden or read-restricted, such as password-reset tokens.