logo

Database

Business information leak In payload

Description

Payload: Sort queries could expose protected field information

Impact

Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.

You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.

Patches

Payload now applies field-level access checks to sort fields before executing queries.

Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds

Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-G1TPN – Vulnerability | Fluid Attacks Database