VDB
KO
HIGH 7.2

GHSA-93vw-8fm5-p2jf

Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks

Details

### Impact

A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server `requestKeywordDenylist` option.

### Patches

Improved keyword detection.

### Workarounds

None.

### Collaborators

Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-93vw-8fm5-p2jf

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 4.10.20
Fix npm install parse-server@4.10.20
npm / parse-server
Introduced in: 5.0.0 Fixed in: 5.3.3
Fix npm install parse-server@5.3.3

References