VDB
KO
CRITICAL 9.8

GHSA-prm5-8g2m-24gg

Remote code execution via MongoDB BSON parser through prototype pollution

Details

### Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

### Patches

Prevent prototype pollution in MongoDB database adapter.

### Workarounds

Disable remote code execution through the MongoDB BSON parser.

### Collaborators

Mikhail Shcherbakov (KTH), Cristian-Alexandru Staicu (CISPA) and Musard Balliu (KTH) working with Trend Micro Zero Day Initiative

### References

- https://github.com/parse-community/parse-server/security/advisories/GHSA-prm5-8g2m-24gg

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / parse-server
Introduced in: 0 Fixed in: 4.10.18
Fix npm install parse-server@4.10.18
npm / parse-server
Introduced in: 5.0.0 Fixed in: 5.3.1
Fix npm install parse-server@5.3.1

References