VDB
Sign up
HIGH

GHSA-jhp4-jvq3-w5xr

Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Quick fix

GHSA-jhp4-jvq3-w5xr — parse-dashboard: upgrade to the fixed version with the command below.

npm install parse-dashboard@9.0.0-alpha.8

Details

### Impact

The `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only user can receive the cached full master key, or a regular user can receive the cached read-only master key.

### Patches

The fix uses distinct cache keys for master key and read-only master key.

### Workarounds

Avoid using function-typed master keys, or remove the `agent` configuration block from your dashboard configuration.

### Resources

- GitHub advisory: https://github.com/parse-community/parse-dashboard/security/advisories/GHSA-jhp4-jvq3-w5xr - Fixed in: https://github.com/parse-community/parse-dashboard/releases/tag/9.0.0-alpha.8

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/parse-dashboard
Introduced in: 7.3.0-alpha.42Fixed in: 9.0.0-alpha.8
Fixnpm install parse-dashboard@9.0.0-alpha.8

References