PT-2023-25584 · Unknown+2 · Parse Server+2

Hir0Ot

·

Published

2023-06-28

·

Updated

2024-03-06

·

CVE-2023-36475

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 5.5.2 and 6.2.1
Description The issue allows an attacker to use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This can be exploited in Parse Server, an open source backend that can be deployed to any infrastructure that can run Node.js.
Recommendations For versions prior to 5.5.2, update to version 5.5.2 to resolve the issue. For versions prior to 6.2.1, update to version 6.2.1 to resolve the issue. As a temporary workaround, consider disabling remote code execution through the MongoDB BSON parser until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BIT-PARSE-2023-36475
CVE-2023-36475
GHSA-462X-C3JW-7VR6
ZDI-23-1160

Affected Products

Mongodb
Node.Js
Parse Server