logo

Database

Spoofing In payload

Description

Payload authentication token field handling issue

Impact

Under certain field configurations, Payload could include unintended values in the authentication token issued at login.

You are affected if:

    You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name.

Patches

Payload now restricts which field configuration options can influence the contents of the authentication token.

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions