GHSA-p96c-xwx8-3cqj: Npm/@payloadcms/plugin-multi-tenant vulnerability
Impact
When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
- You are using @payloadcms/plugin-multi-tenant
If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Configuration
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
@payloadcms/plugin-multi-tenant tenants arrayFieldAccess.create and tenants arrayFieldAccess.update = Only trusted users authorized for all tenants
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user can exploit the default tenant array field access behavior to assign themselves to other tenants. The issue applies to deployments using @payloadcms/plugin-multi-tenant.
Are customized tenant membership controls affected?
Not by this specific default behavior if tenants arrayFieldAccess.create and tenants arrayFieldAccess.update are configured, or if a secured replacement membership field is used.
What can be done before upgrading?
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so that only trusted users authorized for all tenants can modify memberships.
Which versions contain the fix?
Upgrade Payload packages to version 3.90.0 or later, or 4.0.0-canary.34 or later.