PT-2024-32465 · Unknown · Parse Server

Kartal Kaan Bozdoğan

+1

·

Published

2024-10-04

·

Updated

2026-02-25

·

CVE-2024-47183

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 6.5.9 Parse Server versions prior to 7.3.0
Description The issue arises when the Parse Server option allowCustomObjectId: true is set, allowing an attacker to create a new user with a custom object ID that exploits the vulnerability and acquires privileges of a specific role.
Recommendations For versions prior to 6.5.9, update to version 6.5.9 or later to resolve the issue. For versions prior to 7.3.0, update to version 7.3.0 or later to resolve the issue. As a temporary workaround, consider disabling custom object IDs by setting allowCustomObjectId: false. Alternatively, use a Cloud Code Trigger to validate that a new user's object ID doesn't start with the prefix role:.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-PARSE-2024-47183
CVE-2024-47183
GHSA-8XQ9-G7CH-35HG

Affected Products

Parse Server