Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class v…
中危 CVSS 5.3
摘要
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. The sensitive data filter modifies these shared objects in-place, so when one subscriber's filter removes a protected field, subsequent subscribers may receive the already-filtered object. This can ca…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/parse-community/parse-server/commit/5834e29234593addaa0251a85f572ad4f376320b Patch
- https://github.com/parse-community/parse-server/commit/776c71c3078e77d38c94937f463741793609d055 Patch
- https://github.com/parse-community/parse-server/pull/10330 Issue Tracking
- https://github.com/parse-community/parse-server/pull/10331 Issue Tracking
- https://github.com/parse-community/parse-server/security/advisories/GHSA-m983-v2ff-wq65 Patch
时间线
- nvd_ingest NVD