Description
This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.
Recommendation
Update the parse-server
package to the latest compatible version. Followings are version details:
Affected version(s): **>= 7.0.0-alpha.1, < 7.0.0-alpha.20 < 6.5.0** Patched version(s): **7.0.0-alpha.20 6.5.0**
References
Related Issues
- Command injection in Parse Server through prototype pollution - CVE-2022-24760
- NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies - CVE-2025-48947
- Parse Server before v3.4.1 vulnerable to Denial of Service - CVE-2019-1020012
- Strapi allows Server-Side Request Forgery in Webhook function - CVE-2024-52588
- Tags:
- npm
- parse-server
Anything's wrong? Let us know Last updated on March 01, 2024