VDB
Sign up
MEDIUM6.4

GHSA-9f2h-7v79-mxw3

Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs

Quick fix

GHSA-9f2h-7v79-mxw3 — parse: upgrade to the fixed version with the command below.

npm install parse@7.0.0

Details

### Summary

Prototype pollution capabilities on various APIs.

### Details

Injection of malicious payload allows attacker to remotely execute arbitrary code. `Parse.Object` and internal APIs are affected, specifically: - `ParseObject.fromJSON` - `ParseObject.pin` - `ParseObject.registerSubclass` - `ObjectStateMutations` (internal) - `encode`/`decode` (internal)

### PoC

Demonstrative tests added as part of the fix.

### References

- https://github.com/parse-community/Parse-SDK-JS/security/advisories/GHSA-9f2h-7v79-mxw3 - Patch https://github.com/parse-community/Parse-SDK-JS/releases/tag/7.0.0-alpha.1

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse
Introduced in: 0Fixed in: 7.0.0
Fixnpm install parse@7.0.0

References