When using the Stripe payment adapter, an order confirmation could be processed more than once under certain conditions.
You are affected if:
- You use @payloadcms/plugin-ecommerce with the Stripe payment adapter.
Deployments that do not use the Stripe payment flow are not affected.
// patchesUsers should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
// workaroundsEnsure Stripe order confirmations can only be processed once. This is a temporary mitigation; upgrading to a patched version is recommended.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- None
- User interaction
- None
- Confidentiality (vulnerable system)
- None
- Integrity (vulnerable system)
- High
- Availability (vulnerable system)
- High
- Confidentiality (subsequent systems)
- None
- Integrity (subsequent systems)
- None
- Availability (subsequent systems)
- None