Parseplatform

Parse-server

102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 25.06.2026 21:41:01
  • Zuletzt bearbeitet 30.07.2026 14:32:43

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency ...

  • EPSS 0.24%
  • Veröffentlicht 12.05.2026 13:34:50
  • Zuletzt bearbeitet 26.05.2026 16:39:16

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carryi...

  • EPSS 0.19%
  • Veröffentlicht 07.04.2026 19:51:03
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protect...

  • EPSS 0.23%
  • Veröffentlicht 07.04.2026 18:16:43
  • Zuletzt bearbeitet 15.04.2026 17:20:11

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists ...

  • EPSS 0.16%
  • Veröffentlicht 06.04.2026 19:47:27
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with...

  • EPSS 0.38%
  • Veröffentlicht 31.03.2026 19:39:54
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on ...

  • EPSS 0.3%
  • Veröffentlicht 31.03.2026 19:34:50
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, reco...

  • EPSS 0.25%
  • Veröffentlicht 31.03.2026 15:10:06
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level per...

  • EPSS 0.21%
  • Veröffentlicht 31.03.2026 15:08:31
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by...

  • EPSS 0.46%
  • Veröffentlicht 31.03.2026 15:06:33
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by sending a cra...