Improper access control in Parse Server - CVE-2023-41058

 

Improper access control in Parse Server - CVE-2023-41058

Published: September 5, 2023


Vulnerability identifier: #VU80441
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41058
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in Parse Pointer. A remote non-authenticated attacker can access internal Parse Server classes and circumvent beforeFind query trigger to bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Parse Server

How to mitigate CVE-2023-41058

Install updates from vendor's website.

Parse Server - addressed in versions 5.5.5, 6.2.2

External References

Related Security Bulletins