Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-30949

Опубликовано: 10 мар. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak access tokens against the configured client-id. A valid access token issued by the same Keycloak realm for a different client application can be used to authenticate as any user on the Parse Server that uses the Keycloak adapter. This enables cross-application account takeover in multi-client Keycloak realms. All Parse Server deployments that use the Keycloak authentication adapter with a Keycloak realm that has multiple client applications are affected. This vulnerability is fixed in 9.5.2-alpha.5 and 8.6.18.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
Версия до 8.6.18 (исключая)
cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*
Версия от 9.0.0 (включая) до 9.5.2 (исключая)
cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:parseplatform:parse-server:9.5.2:alpha4:*:*:*:node.js:*:*

EPSS

Процентиль: 10%
0.00034
Низкий

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

github
около 1 месяца назад

Parse Server missing audience validation in Keycloak authentication adapter

EPSS

Процентиль: 10%
0.00034
Низкий

8.8 High

CVSS3

Дефекты

CWE-287