PT-2022-26111 · Unknown · Parse Server

Cristian-Alexandru Staicu

+2

·

Published

2022-11-10

·

Updated

2024-03-06

·

CVE-2022-41879

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 5.3.3 Parse Server versions prior to 4.10.20
Description A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server requestKeywordDenylist option. This issue affects Parse Server, an open source backend that can be deployed to any infrastructure that can run Node.js.
Recommendations For versions prior to 5.3.3, update to version 5.3.3 or later. For versions prior to 4.10.20, update to version 4.10.20 or later. As a temporary workaround, consider restricting access to the Cloud Code Webhook target endpoint until a patch is applied.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BIT-PARSE-2022-41879
CVE-2022-41879
GHSA-93VW-8FM5-P2JF
ZDI-22-1592

Affected Products

Parse Server