Parse Server
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:*:*
- >= 9.0.0, < 9.6.0-alpha.28
- < 8.6.48
A vulnerability in Parse Server's password reset mechanism allows tokens to be reused across multiple concurrent requests, prior to versions 9.6.0-alpha.28 and 8.6.48. This flaw enables an attacker who intercepts a reset token to exploit the situation by racing against the legitimate user's request, potentially leading to unauthorized password changes. All Parse Server deployments utilizing the password reset feature are affected.
Exploitation of this vulnerability allows for a password reset token to be reused, potentially leading to unauthorized password changes.
Users can upgrade to Parse Server versions 9.6.0-alpha.28 or 8.6.48, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.