PT-2022-3535 · Unknown · Parse Server

Mtrezzapublished

+1

·

Published

2022-06-17

·

Updated

2024-03-06

·

CVE-2022-31083

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 4.10.11 and 5.2.2
Description The issue is related to the lack of validation of the certificate in the Parse Server Apple Game Center auth adapter. This could potentially allow authentication to be bypassed by making a fake certificate accessible via certain Apple domains and providing the URL to that certificate in an authData object.
Recommendations For versions prior to 4.10.11 and 5.2.2, update to version 4.10.11 or 5.2.2 to introduce a new rootCertificateUrl property to the Parse Server Apple Game Center auth adapter, which takes the URL to the root certificate of Apple's Game Center authentication certificate. Ensure the rootCertificateUrl property is kept up-to-date as the root certificate can change at any time.

Exploit

Fix

Improper Authentication

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2022-04318
BIT-PARSE-2022-31083
CVE-2022-31083
GHSA-RH9J-F5F8-RVGC

Affected Products

Parse Server