VDB
KO
HIGH 7.5

GHSA-h423-w6qv-2wj3

parse-server crashes when receiving file download request with invalid byte range

Details

### Impact

Parse Server crashes when a file download request is received with an invalid byte range.

### Patches

Improved parsing of the range parameter to properly handle invalid range requests.

### Workarounds

None

### References

- [GHSA-h423-w6qv-2wj3](https://github.com/parse-community/parse-server/security/advisories/GHSA-h423-w6qv-2wj3)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 4.10.17
Fix npm install parse-server@4.10.17
npm / parse-server
Introduced in: 5.0.0 Fixed in: 5.2.8
Fix npm install parse-server@5.2.8

References