Описание
Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks
Impact
A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server requestKeywordDenylist option.
Patches
Improved keyword detection.
Workarounds
None.
Collaborators
Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative
References
Ссылки
- https://github.com/parse-community/parse-server/security/advisories/GHSA-93vw-8fm5-p2jf
- https://nvd.nist.gov/vuln/detail/CVE-2022-41879
- https://github.com/parse-community/parse-server/pull/8305
- https://github.com/parse-community/parse-server/pull/8306
- https://github.com/parse-community/parse-server/commit/60c5a73d257e0d536056b38bdafef8b7130524d8
- https://github.com/parse-community/parse-server/commit/6c63f04ba37174021082a5b5c4ba1556dcc954f4
- https://github.com/parse-community/parse-server/releases/tag/4.10.20
- https://github.com/parse-community/parse-server/releases/tag/5.3.3
Пакеты
parse-server
< 4.10.20
4.10.20
parse-server
>= 5.0.0, < 5.3.3
5.3.3
Связанные уязвимости
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server `requestKeywordDenylist` option. This issue has been patched in versions 5.3.3 and 4.10.20. There are no known workarounds.