Improper authorization control for web services In payload
Description
Payload relationship-query authorization bypass
Impact
A readable collection could expose information about protected documents in a related collection.
You are affected if:
You expose a readable collection with a relationship to a collection protected by access.read where constraints.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Upgrade Payload packages >= 3.90.0 or >= 4.0.0-canary.34.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.