10

CVE-2024-27298

Parse Server literalizeRegexPart SQL Injection

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Parseplatform ≫ Parse-server SwPlatform node.js Version < 6.5.0
Parseplatform ≫ Parse-server Version 6.5.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 6.5.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 6.5.0 Update beta1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha1 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha10 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha11 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha12 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha13 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha14 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha15 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha16 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha17 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha18 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha19 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha2 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha3 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha4 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha5 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha6 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha7 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha8 SwPlatform node.js
Parseplatform ≫ Parse-server Version 7.0.0 Update alpha9 SwPlatform node.js
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504
Patch
https://github.com/parse-community/parse-server/commit/cbefe770a7260b54748a058b8a7389937dc35833
Patch
https://github.com/parse-community/parse-server/releases/tag/6.5.0
Release Notes
https://github.com/parse-community/parse-server/releases/tag/7.0.0-alpha.20
Release Notes
https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2
Vendor Advisory