CRITICAL 9.8 npm

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

GHSA-462x-c3jw-7vr6 · BIT-parse-2023-36475 · CVE-2023-36475

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

Patches

Prevent prototype pollution in MongoDB database adapter.

Workarounds

Disable remote code execution through the MongoDB BSON parser.

Credits

  • Discovered by hir0ot working with Trend Micro Zero Day Initiative
  • Fixed by dbythy
  • Reviewed by mtrezza

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes