SB2019071137 - Observable discrepancy in parse-server



SB2019071137 - Observable discrepancy in parse-server

Published: July 11, 2019 Updated: May 23, 2026

Security Bulletin ID SB2019071137
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Observable discrepancy (CVE-ID: CVE-2019-1020013)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information about linked accounts and email addresses.

The vulnerability exists due to improper access control in the account linking functionality when handling account linking requests. A remote attacker can guess account identifiers and observe different error responses to disclose sensitive information about linked accounts and email addresses.

The issue arises because different errors are returned before insufficient authorization is checked.


Remediation

Install update from vendor's website.