ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
53Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.8epss 20%
de la publicación al arma463 días
Publicada en NVD1 jul
1ª PoC+463d
probabilidad de explotación
20%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
parse-community · parse-serverPoCs públicas encontradas — 1
githubgithub.com/HeavyGhost-le/POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0★ 1⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/parse-community/parse-server/commit/2edf1e4c0363af01e97a7fbc97694f851b7d1ff3https://github.com/parse-community/parse-server/commit/f332d54577608c5ad927255e06d8c694e2e0ff5bhttps://github.com/parse-community/parse-server/pull/9167https://github.com/parse-community/parse-server/pull/9168https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r