VDB
Sign up
CRITICAL10.0

GHSA-6927-3vr9-fxf2

ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection

Quick fix

GHSA-6927-3vr9-fxf2 — parse-server: upgrade to the fixed version with the command below.

npm install parse-server@6.5.0

Details

### Impact

This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.

### Patches

The algorithm to detect SQL injection has been improved.

### Workarounds

None.

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2 - https://github.com/parse-community/parse-server/releases/tag/6.5.0 (fixed in Parse Server 6) - https://github.com/parse-community/parse-server/releases/tag/7.0.0-alpha.20 (fixed in Parse Server 7 alpha release)

### Credits

- Mikhail Shcherbakov (https://twitter.com/yu5k3) working with Trend Micro Zero Day Initiative (finder) - Ehsan Persania (remediation developer) - Manuel Trezza (coordinator)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-server
Introduced in: 0Fixed in: 6.5.0
Fixnpm install parse-server@6.5.0
npm/parse-server
Introduced in: 7.0.0-alpha.1Fixed in: 7.0.0-alpha.20
Fixnpm install parse-server@7.0.0-alpha.20

References