Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93vw-8fm5-p2jf

Опубликовано: 10 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks

Impact

A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server requestKeywordDenylist option.

Patches

Improved keyword detection.

Workarounds

None.

Collaborators

Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative

References

Пакеты

Наименование

parse-server

npm
Затронутые версииВерсия исправления

< 4.10.20

4.10.20

Наименование

parse-server

npm
Затронутые версииВерсия исправления

>= 5.0.0, < 5.3.3

5.3.3

EPSS

Процентиль: 63%
0.00438
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server `requestKeywordDenylist` option. This issue has been patched in versions 5.3.3 and 4.10.20. There are no known workarounds.

EPSS

Процентиль: 63%
0.00438
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321