← back
CVE-2023-36475criticalCWE-1321

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 3.2%
exploitation probability
3.2%top 12% of all CVEs
observed exploitation
nono source reports it
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H