Improper authorization control for web services In @payloadcms/plugin-multi-tenant
Description
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
Impact
An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.
Reads and direct edits to an existing target-tenant document were not bypassed.
You are affected if:
You are using @payloadcms/plugin-multi-tenant
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
References