Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator ac…
严重 CVSS 9.1
摘要
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the v…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/parse-community/parse-server/commit/4fc48cf28f22eea200d74d883505f485234a48d7 Patch
- https://github.com/parse-community/parse-server/commit/dc59e272665644083c5b7f6862d88ce1ef0b2674 Patch
- https://github.com/parse-community/parse-server/pull/10342 Issue Tracking
- https://github.com/parse-community/parse-server/pull/10343 Issue Tracking
- https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6 Mitigation
时间线
- nvd_ingest NVD