VDB
EN
HIGH 7.7

GHSA-4w46-w44m-3jq3

Parse Server stores password in plain text

상세

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / parse-server
최초 영향 버전: 0 수정 버전: 4.5.0
수정 npm install parse-server@4.5.0

참고