Parse Server
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*, +1 more
- >= 9.3.1-alpha.3, < 9.5.0-alpha.10
A vulnerability in Parse Server versions 9.3.1-alpha.3 prior to 9.5.0-alpha.10 allows unauthenticated users to bypass GraphQL introspection controls. When the 'graphQLPublicIntrospection' feature is disabled, '__type' queries nested within inline fragments can be exploited to perform type reconnaissance. This issue does not affect '__schema' introspection.
Exploitation of this vulnerability allows for unauthorized type reconnaissance via GraphQL introspection.
Users can upgrade to Parse Server version 9.5.0-alpha.10, where this vulnerability has been patched. Alternatively, the GraphQL endpoint can be configured to require master key authentication at the network layer.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.