VDB
Sign up
MEDIUM6.5

GHSA-9g8m-v378-pcg3

parse is vulnerable to prototype pollution

Quick fix

GHSA-9g8m-v378-pcg3 — parse: upgrade to the fixed version with the command below.

npm install parse@7.0.0-alpha.1

Details

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse
Introduced in: 0Fixed in: 7.0.0-alpha.1
Fixnpm install parse@7.0.0-alpha.1

References