Parse Server
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*, +1 more
- >= 9.0.0, < 9.5.2-alpha.6
- < 8.6.19
A vulnerability in Parse Server prior to versions 9.5.2-alpha.6 and 8.6.19 allows authenticated users to bypass validation on protected fields. The issue arises because the validation only considers top-level query keys. By enclosing a query constraint for a protected field within a logical operator, the validation is completely circumvented. This flaw enables extraction of field values from protected areas. All default Parse Server deployments are affected.
Exploitation of this vulnerability allows authenticated users to query protected fields and retrieve sensitive data from those fields.
Users can update to Parse Server versions 9.5.2-alpha.6 or 8.6.19 to address this vulnerability. Alternatively, a 'beforeFind' trigger can be used on affected classes to manually check queries for references to protected fields in logical operator sub-queries and reject those requests.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.