PT-2022-24895 · Unknown · Parse Server

Hej2010

·

Published

2022-10-18

·

Updated

2024-03-06

·

CVE-2022-39313

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 4.10.17 Parse Server versions prior to 5.2.8 on the 5.x branch
Description The issue occurs when a file download request is received with an invalid byte range, causing the server to crash and resulting in a Denial of Service. The problem has been patched in versions 4.10.17 and 5.2.8.
Recommendations For versions prior to 4.10.17, update to version 4.10.17 or later. For versions prior to 5.2.8 on the 5.x branch, update to version 5.2.8 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-PARSE-2022-39313
CVE-2022-39313
GHSA-H423-W6QV-2WJ3

Affected Products

Parse Server