VDB
EN
CRITICAL 9.8

GHSA-c2hr-cqg6-8j6r

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

상세

### Impact

This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.

### Patches

The algorithm to detect SQL injection has been improved.

### Workarounds

None.

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r - https://github.com/parse-community/parse-server/pull/9167 (fix for Parse Server 7) - https://github.com/parse-community/parse-server/pull/9168 (fix for Parse Server 6)

### Credits

- Smile Thanapattheerakul of Trend Micro (finder) - Manuel Trezza (coordinator)

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / parse-server
최초 영향 버전: 0 수정 버전: 6.5.7
수정 npm install parse-server@6.5.7
npm / parse-server
최초 영향 버전: 7.0.0 수정 버전: 7.1.0
수정 npm install parse-server@7.1.0

참고