Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication pr…
Medium CVSS 4.4
Summary
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery code or SMS one-time password can create multiple authenticated sessions by sending concurrent login requests via the authData login endpoint. This defeats the single-use guarantee of MFA recovery codes and SMS one-time passwords, allowing session persistence e…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/parse-community/parse-server/commit/661f160edac8daac0486bc94413cf9652876ab92 Patch
- https://github.com/parse-community/parse-server/commit/e7efbebba398ce6abe5b6b6fb9829c6ebe310fbf Patch
- https://github.com/parse-community/parse-server/pull/10326 Issue Tracking
- https://github.com/parse-community/parse-server/pull/10327 Issue Tracking
- https://github.com/parse-community/parse-server/security/advisories/GHSA-w73w-g5xw-rwhf Patch
Timeline
- nvd_ingest NVD