VDB
Sign up
CRITICAL9.8

GHSA-c2hr-cqg6-8j6r

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

Quick fix

GHSA-c2hr-cqg6-8j6r — parse-server: upgrade to the fixed version with the command below.

npm install parse-server@6.5.7

Details

### Impact

This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.

### Patches

The algorithm to detect SQL injection has been improved.

### Workarounds

None.

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-c2hr-cqg6-8j6r - https://github.com/parse-community/parse-server/pull/9167 (fix for Parse Server 7) - https://github.com/parse-community/parse-server/pull/9168 (fix for Parse Server 6)

### Credits

- Smile Thanapattheerakul of Trend Micro (finder) - Manuel Trezza (coordinator)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-server
Introduced in: 0Fixed in: 6.5.7
Fixnpm install parse-server@6.5.7
npm/parse-server
Introduced in: 7.0.0Fixed in: 7.1.0
Fixnpm install parse-server@7.1.0

References