PT-2024-28434 · Unknown+1 · Parse Server+1
Smile Thanapattheerakul
·
Published
2024-07-01
·
Updated
2024-07-10
·
CVE-2024-39309
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 6.5.7
Parse Server versions prior to 7.1.0
Description
A vulnerability in Parse Server allows SQL injection when configured to use the PostgreSQL database. This issue enables remote attackers to bypass authentication on affected installations. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. The vulnerability can be exploited without requiring authentication.
Recommendations
For versions prior to 6.5.7, update to version 6.5.7 or later to resolve the issue.
For versions prior to 7.1.0, update to version 7.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the PostgreSQL database until a patch is applied. Avoid using the
literalizeRegexPart function in the affected API endpoints until the issue is resolved.Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Parse Server
Postgresql