PT-2024-28434 · Unknown+1 · Parse Server+1

Smile Thanapattheerakul

·

Published

2024-07-01

·

Updated

2024-07-10

·

CVE-2024-39309

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 6.5.7 Parse Server versions prior to 7.1.0
Description A vulnerability in Parse Server allows SQL injection when configured to use the PostgreSQL database. This issue enables remote attackers to bypass authentication on affected installations. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. The vulnerability can be exploited without requiring authentication.
Recommendations For versions prior to 6.5.7, update to version 6.5.7 or later to resolve the issue. For versions prior to 7.1.0, update to version 7.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the PostgreSQL database until a patch is applied. Avoid using the literalizeRegexPart function in the affected API endpoints until the issue is resolved.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

SQL injection

Weakness Enumeration

Related Identifiers

BIT-PARSE-2024-39309
CVE-2024-39309
GHSA-C2HR-CQG6-8J6R
ZDI-24-896

Affected Products

Parse Server
Postgresql