#VU80441 Improper access control in Parse Server - CVE-2023-41058
Published: September 5, 2023
Parse Server
Parse Community
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Parse Pointer. A remote non-authenticated attacker can access internal Parse Server classes and circumvent beforeFind query trigger to bypass implemented security restrictions and gain unauthorized access to the application.
Remediation
External links
- https://github.com/parse-community/parse-server/commit/be4c7e23c63a2fb690685665cebed0de26be05c5
- https://github.com/parse-community/parse-server/releases/tag/6.2.2
- https://github.com/parse-community/parse-server/security/advisories/GHSA-fcv6-fg5r-jm9q
- https://github.com/parse-community/parse-server/releases/tag/5.5.5