Description
If a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.
Affected versions: < 1.7.0
Recommendation
Update the payload package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.7.0
- Patched version(s): 1.7.0
References
Related Issues
- Matrix IRC Bridge truncated content of messages can be leaked - CVE-2024-32000
- Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS) - CVE-2023-25653
- Leaking sensitive user information still possible by filtering on private with prefix fields - @strapi/database - CVE-2023-34235
- Leaking sensitive user information still possible by filtering on private with prefix fields - CVE-2023-34235
You might also like:
- Tags:
- npm
- payload
Anything's wrong? Let us know Last updated on November 11, 2023


