Vulnerabilities/

Hidden fields can be leaked on readable collections in Payload

Severity:
High

Description

If a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.

Affected versions: < 1.7.0

Recommendation

Update the payload package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
payload
Anything's wrong? Let us know Last updated on November 11, 2023

This issue is available in SmartScanner Professional

See Pricing