Business information leak In payload
Description
Payload: Sort queries could expose protected field information
Impact
Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.
You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
Patches
Payload now applies field-level access checks to sort fields before executing queries.
Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.88.0, 4.0.0-canary.27 |
Aliases
References