HIGH 7.5 npm
Parse Server crashes with query parameter
GHSA-xqp8-w826-hh6x · BIT-parse-2021-39187 · CVE-2021-39187
Published · Modified
Description
Impact
Parse Server crashes when if a query request contains an invalid value for the explain option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch.
Patches
Upgrade to Parse Server 4.10.3
References
- WEB https://github.com/parse-community/parse-server/security/advisories/GHSA-xqp8-w826-hh6x
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-39187
- WEB https://github.com/parse-community/parse-server/commit/308668c89474223e2448be92d6823b52c1c313ec
- PACKAGE https://github.com/parse-community/parse-server
- WEB https://github.com/parse-community/parse-server/releases/tag/4.10.3
- WEB https://jira.mongodb.org/browse/NODE-3463
Ready to move
Start Securing
Free, no credit card | First findings in minutes