HIGH 8.1 npm
Parse Server's custom object ID allows to acquire role privileges
GHSA-8xq9-g7ch-35hg · BIT-parse-2024-47183 · CVE-2024-47183
Published · Modified
Description
Impact
If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role.
Patches
Improved validation for custom user object IDs. Session tokens for existing users with an object ID that exploits the vulnerability are now rejected.
Workarounds
- Disable custom object IDs by setting
allowCustomObjectId: falseor not setting the option which defaults tofalse. - Use a Cloud Code Trigger to validate that a new user's object ID doesn't start with the prefix
role:.
References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg
- https://github.com/parse-community/parse-server/pull/9317 (fix for Parse Server 7)
- https://github.com/parse-community/parse-server/pull/9318 (fix for Parse Server 6)
References
- WEB https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-47183
- WEB https://github.com/parse-community/parse-server/pull/9317
- WEB https://github.com/parse-community/parse-server/pull/9318
- WEB https://github.com/parse-community/parse-server/commit/13ee52f0d19ef3a3524b3d79aea100e587eb3cfc
- WEB https://github.com/parse-community/parse-server/commit/1bfbccf9ee7ea77533b2b2aa7c4c69f3bd35e66f
- PACKAGE https://github.com/parse-community/parse-server
Ready to move
Start Securing
Free, no credit card | First findings in minutes