Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator ac…
Critical CVSS 9.1
Summary
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the v…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/parse-community/parse-server/commit/4fc48cf28f22eea200d74d883505f485234a48d7 Patch
- https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674 Patch
- https://github.com/parse-community/parse-server/pull/10342 Issue Tracking
- https://github.com/parse-community/parse-server/pull/10343 Issue Tracking
- https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6 Mitigation
Timeline
- nvd_ingest NVD