Description
If a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.
Affected versions: < 1.7.0
Recommendation
Update the payload package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.7.0
- Patched version(s): 1.7.0
References
Related Issues
- angular vulnerable to super-linear runtime due to backtracking - CVE-2024-21490
- Payload's SQLite adapter Session Fixation vulnerability (GHSA-26rv-h2hf-3fw4) 2 - CVE-2025-4644
- Payload does not invalidate JWTs after log out (GHSA-5v66-m237-hwf7) 2 - CVE-2025-4643
- Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772
- Tags:
- npm
- payload
Anything's wrong? Let us know Last updated on November 11, 2023