Описание
Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.3.0 (включая)
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 48%
0.00253
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-672
CWE-672
Связанные уязвимости
CVSS3: 4.3
github
больше 5 лет назад
receiving subscription objects with deleted session
EPSS
Процентиль: 48%
0.00253
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-672
CWE-672