Spoofing In payload
Description
Payload authentication token field handling issue
Impact
Under certain field configurations, Payload could include unintended values in the authentication token issued at login.
You are affected if:
You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name.
Patches
Payload now restricts which field configuration options can influence the contents of the authentication token.
Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
References