Описание
Invalid push request payload crashes Parse Server
Impact
The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload.
Patches
Invalid push notification payload is caught and an logged.
Workarounds
n/a
References
Ссылки
- https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993
- https://nvd.nist.gov/vuln/detail/CVE-2023-32688
- https://github.com/parse-community/parse-server-push-adapter/pull/217
- https://github.com/parse-community/parse-server-push-adapter/commit/598cb84d0866b7c5850ca96af920e8cb5ba243ec
- https://github.com/parse-community/parse-server-push-adapter/releases/tag/4.1.3
Пакеты
Наименование
parse-server-push-adapter
npm
Затронутые версииВерсия исправления
< 4.1.3
4.1.3
Связанные уязвимости
CVSS3: 4.9
nvd
больше 2 лет назад
parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload. This issue has been patched in version 4.1.3.