Non-encrypted confidential information In @payloadcms/plugin-ecommerce
Description
Payload Ecommerce has an order confirmation validation issue
Impact
When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.
You are affected if:
You use @payloadcms/plugin-ecommerce with the Stripe payment adapter.
Deployments that do not use the Stripe payment flow are not affected.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Ensure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 |
Aliases
References