Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37mj-c2wf-cx96

Опубликовано: 24 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Parse Server exposes auth data via /users/me endpoint

Impact

An authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user's session token can extract MFA secrets to generate valid TOTP codes indefinitely.

Patches

The /users/me endpoint now queries the session and user data separately, using the caller's authentication context for the user query so that all security layers apply correctly.

Workarounds

There is no known workaround.

Пакеты

Наименование

parse-server

npm
Затронутые версииВерсия исправления

>= 9.0.0, < 9.6.0-alpha.55

9.6.0-alpha.55

Наименование

parse-server

npm
Затронутые версииВерсия исправления

< 8.6.61

8.6.61

EPSS

Процентиль: 31%
0.00378
Низкий

7.1 High

CVSS4

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes. The endpoint internally uses master-level authentication for the session query, and the master context leaks through to the user data, bypassing auth adapter sanitization. An attacker who obtains a user's session token can extract MFA secrets to generate valid TOTP codes indefinitely. This issue has been patched in versions 8.6.61 and 9.6.0-alpha.55.

EPSS

Процентиль: 31%
0.00378
Низкий

7.1 High

CVSS4

Дефекты

CWE-200