VDB
Sign up
CRITICAL9.8

GHSA-462x-c3jw-7vr6

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Quick fix

GHSA-462x-c3jw-7vr6 — parse-server: upgrade to the fixed version with the command below.

npm install parse-server@5.5.2

Details

### Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

### Patches

Prevent prototype pollution in MongoDB database adapter.

### Workarounds

Disable remote code execution through the MongoDB BSON parser.

### Credits

- Discovered by hir0ot working with Trend Micro Zero Day Initiative - Fixed by dbythy - Reviewed by mtrezza

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-462x-c3jw-7vr6 - https://github.com/advisories/GHSA-prm5-8g2m-24gg

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-server
Introduced in: 0Fixed in: 5.5.2
Fixnpm install parse-server@5.5.2
npm/parse-server
Introduced in: 6.0.0Fixed in: 6.2.1
Fixnpm install parse-server@6.2.1

References