CVE-2021-47987: fallo de gravedad alta en parse-community parse-server
Parse Server - Arbitrary Code Execution via Malicious Version Tags
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.7epss 0.2%
probabilidad de explotación
0.2%top 93% de las CVE
explotación observada
noninguna fuente lo reporta
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
parse-community · parse-serverCVEs relacionadas — parse-community parse-server
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-24760CRITICALCommand Injection in Parse serverEPSS 49.1%CVE-2022-39396CRITICALParse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parserEPSS 38.7%CVE-2024-39309CRITICALZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass VulnerabilityEPSS 20.2%CVE-2023-36475CRITICALParse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollutionEPSS 3.2%CVE-2021-39187HIGHCrash server with query parameterEPSS 1.8%CVE-2026-30965CRITICALParse Server session token exfiltration via `redirectClassNameForKey` query parameterEPSS 1.6%