Parse Server
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*
- >= 9.0.0, < 9.6.0-alpha.6
- < 8.6.32
A vulnerability in Parse Server prior to versions 9.6.0-alpha.6 and 8.6.32 allows for bypassing the protectedFields class-level permission. This is achieved through dot-notation in query WHERE clauses and sort parameters, enabling a binary oracle attack to enumerate protected field values. The issue affects both MongoDB and PostgreSQL deployments.
Exploitation of this vulnerability allows attackers to bypass class-level permissions on protected fields, enabling them to query or sort by sub-fields of these protected fields. This could lead to unauthorized access to sensitive data.
Users can upgrade to Parse Server versions 9.6.0-alpha.6 or 8.6.32 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.