GHSA-9g87-32v6-3c2rMedium
Payload: Sort queries could expose protected field information
🔗 CVE IDs covered (1)
📋 Description
Impact
Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.
You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
Patches
Payload now applies field-level access checks to sort fields before executing queries.
Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds
Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.
🎯 Affected products2
- npm/payload:< 3.88.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.27