HIGH 7.5
GHSA-qf8x-vqjv-92gr
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
상세
### Impact Weak validation of the Apple certificate URL in the Apple Game Center authentication adapter allows to bypass authentication and makes the server vulnerable to DoS attacks.
### Patches The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-24901 [ADVISORY]
- https://github.com/parse-community/parse-server/commit/af4a0417a9f3c1e99b3793806b4b18e04d9fa999 [WEB]
- https://github.com/parse-community/parse-server [WEB]