Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-462x-c3jw-7vr6

Опубликовано: 30 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

Patches

Prevent prototype pollution in MongoDB database adapter.

Workarounds

Disable remote code execution through the MongoDB BSON parser.

Credits

  • Discovered by hir0ot working with Trend Micro Zero Day Initiative
  • Fixed by dbythy
  • Reviewed by mtrezza

References

Пакеты

Наименование

parse-server

npm
Затронутые версииВерсия исправления

< 5.5.2

5.5.2

Наименование

parse-server

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.1

6.2.1

EPSS

Процентиль: 92%
0.07546
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.

EPSS

Процентиль: 92%
0.07546
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321