Логотип exploitDog
bind:CVE-2020-15270
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15270

Количество 2

Количество 2

nvd логотип

CVE-2020-15270

больше 5 лет назад

Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xm2-xj2q-qgpj

больше 5 лет назад

receiving subscription objects with deleted session

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15270

Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.

CVSS3: 4.3
0%
Низкий
больше 5 лет назад
github логотип
GHSA-2xm2-xj2q-qgpj

receiving subscription objects with deleted session

CVSS3: 4.3
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу