Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 npm

Sensitive Data Exposure in parse-server

GHSA-8w3j-g983-8jh5 · CVE-2019-1020013

Published · Modified

Description

Versions of parse-server prior to 3.6.0 could allow an account enumeration attack via account linking.
ParseError.ACCOUNT_ALREADY_LINKED(208) was thrown BEFORE the AuthController checks the password and throws a ParseError.SESSION_MISSING(206) for Insufficient auth. An attacker can guess ids and get information about linked accounts/email addresses.

For more information

If you have any questions or comments about this advisory,
Open an issue in the parse-server
Parse Community Vulnerability Disclosure Program

Ready to move

Start Securing

Free, no credit card | First findings in minutes