GHSA-xhm9-gwgw-3q2q: Npm/@payloadcms/plugin-multi-tenant vulnerability
Impact An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.
Reads and direct edits to an existing target-tenant document were not bypassed.
You are affected if: - You are using @payloadcms/plugin-multi-tenant
Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
@payloadcms/plugin-multi-tenantto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Configuration
Configure accessResultOverride on the multi-tenant collection to ensure a user has access to the tenant before creating a record.
@payloadcms/plugin-multi-tenant accessResultOverride = require tenant access before creation
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using @payloadcms/plugin-multi-tenant with at least one tenant-enabled collection are affected. The issue applies to authenticated users who are restricted to a single tenant.
What can an attacker do, and what access do they need?
An authenticated user limited to one tenant can create a record in another tenant. The issue does not bypass reads or direct edits to existing documents in the target tenant.
Which versions contain a fix?
Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.
What can be done if upgrading is not immediately possible?
Add access control using accessResultOverride in the multi-tenant collection configuration. This should verify that the user has access to the tenant before allowing record creation.