Account lockout In payload
Description
Payload: Unauthenticated account-lockout denial of service
Impact
An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.
You are affected if:
Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.
Applications that do not use Payload local authentication are not affected.
Patches
Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
References