GHSA-q6mq-ch85-c8mm: Npm/payload vulnerability
Impact The password-hashing configuration used a lower work factor than what is recommended.
Patches Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Compensating control
Until upgrading, protect database copies and backups from unauthorized access and require strong, unique passwords.
Event History
Frequently Asked Questions
What must an attacker obtain to take advantage of the weaker password hashing?
An attacker would need unauthorized access to database copies or backups containing password hashes. The recommended interim mitigation is to protect those copies and backups and require strong, unique passwords.
What happens to existing password hashes after upgrading?
Payload transparently upgrades older hashes after a user successfully logs in. Upgrading to Payload >= 3.90.0 or >= 4.0.0-canary.34 enables the stronger password-hashing parameters.