Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

Parse Server crashes with query parameter

GHSA-xqp8-w826-hh6x · BIT-parse-2021-39187 · CVE-2021-39187

Published · Modified

Description

Impact

Parse Server crashes when if a query request contains an invalid value for the explain option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch.

Patches

Upgrade to Parse Server 4.10.3

Ready to move

Start Securing

Free, no credit card | First findings in minutes