VDB
KO
CRITICAL 9.8

GHSA-c2hr-cqg6-8j6r

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

Details

### Impact

This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.

### Patches

The algorithm to detect SQL injection has been improved.

### Workarounds

None.

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r - https://github.com/parse-community/parse-server/pull/9167 (fix for Parse Server 7) - https://github.com/parse-community/parse-server/pull/9168 (fix for Parse Server 6)

### Credits

- Smile Thanapattheerakul of Trend Micro (finder) - Manuel Trezza (coordinator)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 6.5.7
Fix npm install parse-server@6.5.7
npm / parse-server
Introduced in: 7.0.0 Fixed in: 7.1.0
Fix npm install parse-server@7.1.0

References