SQL injection In @payloadcms/db-d1-sqlite
Description
Payload: SQL injection in SQLite/Postgres
Impact
An attacker who has read plus create or update access to a collection can submit a request that includes a SQL injection targeting a specific field path shape and operators in Payload's SQLite and Postgres.
You are affected if:
You use @payloadcms/db-sqlite or @payloadcms/db-d1-sqlite.
You use @payloadcms/db-postgres or @payloadcms/db-vercel-postgres < 3.73.0.
A readable collection has a json field, or a blocks field with blocksAsJSON: true.
The attacker has read plus create or update access on it.
You are not affected if:
You have no json or blocksAsJSONfields.richText` is not affected.
You run a patched version.
Patches
The patched version sanitizes the query input to prevent injection.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.90.0, 4.0.0-canary.34 | ||
npm | 3.90.0, 4.0.0-canary.34 | ||
npm | 3.73.0 | ||
npm | 3.73.0 |
Aliases
References