MEDIUM 6.5 npm

GraphQL: Security breach on Viewer query

GHSA-236h-rqv8-8q73 · CVE-2020-15126

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.

Patches

This vulnerability has been patched in Parse Server 4.3.0.

Workarounds

No

References

See commit 78239ac for details.

Ready to move

Start Securing

Free, no credit card | First findings in minutes