VDB
KO
CRITICAL 10.0

GHSA-6927-3vr9-fxf2

ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection

Details

### Impact

This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.

### Patches

The algorithm to detect SQL injection has been improved.

### Workarounds

None.

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2 - https://github.com/parse-community/parse-server/releases/tag/6.5.0 (fixed in Parse Server 6) - https://github.com/parse-community/parse-server/releases/tag/7.0.0-alpha.20 (fixed in Parse Server 7 alpha release)

### Credits

- Mikhail Shcherbakov (https://twitter.com/yu5k3) working with Trend Micro Zero Day Initiative (finder) - Ehsan Persania (remediation developer) - Manuel Trezza (coordinator)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 6.5.0
Fix npm install parse-server@6.5.0
npm / parse-server
Introduced in: 7.0.0-alpha.1 Fixed in: 7.0.0-alpha.20
Fix npm install parse-server@7.0.0-alpha.20

References