Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 npm

GraphQL: Security breach on Viewer query

GHSA-236h-rqv8-8q73 · CVE-2020-15126

Published · Modified

Description

Impact

An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.

Patches

This vulnerability has been patched in Parse Server 4.3.0.

Workarounds

No

References

See commit 78239ac for details.

Ready to move

Start Securing

Free, no credit card | First findings in minutes