Information Exposure Affecting payload package, versions <1.7.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-PAYLOAD-5487992
  • published27 Apr 2023
  • disclosed27 Apr 2023
  • creditcpaczek

Introduced: 27 Apr 2023

CVE-2023-30843  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade payload to version 1.7.0 or higher.

Overview

payload is a Node, React and MongoDB Headless CMS and Application Framework

Affected versions of this package are vulnerable to Information Exposure such that, if a user has access to documents that contain hidden fields or fields they do not have access to, the user could reverse-engineer those values via brute force.

Workaround

Users who are unable to upgrade to the fixed version can write a beforeOperation hook to remove where queries that attempt to access hidden field data.

CVSS Base Scores

version 3.1