Unknown · Parse Server · CVE-2022-39313
**Name of the Vulnerable Software and Affected Versions**
Parse Server versions prior to 4.10.17
Parse Server versions prior to 5.2.8 on the 5.x branch
**Description**
The issue occurs when a file download request is received with an invalid byte range, causing the server to crash and resulting in a Denial of Service. The problem has been patched in versions 4.10.17 and 5.2.8.
**Recommendations**
For versions prior to 4.10.17, update to version 4.10.17 or later.
For versions prior to 5.2.8 on the 5.x branch, update to version 5.2.8 or later.