Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41878

Опубликовано: 10 нояб. 2022
Источник: nvd
CVSS3: 7.2
CVSS3: 9.8
EPSS Низкий

Описание

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option requestKeywordDenylist can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the requestKeywordDenylist option. This issue is fixed in versions 4.10.19, and 5.3.2. If upgrade is not possible, the following Workarounds may be applied: Configure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
Версия до 4.10.19 (исключая)
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
Версия от 5.0.0 (включая) до 5.3.2 (исключая)

EPSS

Процентиль: 66%
0.00514
Низкий

7.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-1321

Связанные уязвимости

CVSS3: 7.2
github
около 3 лет назад

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

EPSS

Процентиль: 66%
0.00514
Низкий

7.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-1321