GHSA-fx49-4h83-wjv9High
Payload didn't enforce field-level password update restrictions
🔗 CVE IDs covered (1)
📋 Description
Impact
When an auth collection defined a field-level access.update restriction on the password field, the restriction was not enforced on the server correctly.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
🎯 Affected products2
- npm/payload:< 3.90.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34