GHSA-7c34-32v3-j575Medium
Payload relationship-query authorization bypass
🔗 CVE IDs covered (1)
📋 Description
Impact
A readable collection could expose information about protected documents in a related collection.
You are affected if:
- You expose a readable collection with a relationship to a collection protected by access.read where constraints.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Upgrade Payload packages >= 3.90.0 or >= 4.0.0-canary.34.
🎯 Affected products2
- npm/payload:< 3.90.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34