VDB
KO
CRITICAL 9.8

GHSA-462x-c3jw-7vr6

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Details

### Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

### Patches

Prevent prototype pollution in MongoDB database adapter.

### Workarounds

Disable remote code execution through the MongoDB BSON parser.

### Credits

- Discovered by hir0ot working with Trend Micro Zero Day Initiative - Fixed by dbythy - Reviewed by mtrezza

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-462x-c3jw-7vr6 - https://github.com/advisories/GHSA-prm5-8g2m-24gg

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 5.5.2
Fix npm install parse-server@5.5.2
npm / parse-server
Introduced in: 6.0.0 Fixed in: 6.2.1
Fix npm install parse-server@6.2.1

References