CVE-2023-32689
- EPSS 0.34%
- Veröffentlicht 30.05.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 08:03:51
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnerable to a phishing attack vulnerability that involves a user uploading malicious files. A malicious us...
CVE-2023-22474
- EPSS 0.26%
- Veröffentlicht 03.02.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:44:52
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server uses the request header `x-forwarded-for` to determine the client IP address. If Parse Server doesn't run behind a proxy server, then...
CVE-2022-41878
- EPSS 0.51%
- Veröffentlicht 10.11.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 07:23:58
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud C...
CVE-2022-41879
- EPSS 0.44%
- Veröffentlicht 10.11.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:23:58
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution...
CVE-2022-39396
- EPSS 10.99%
- Veröffentlicht 10.11.2022 01:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can ...
CVE-2022-39313
- EPSS 0.32%
- Veröffentlicht 24.10.2022 14:15:51
- Zuletzt bearbeitet 21.11.2024 07:18:00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, result...
CVE-2022-39231
- EPSS 0.19%
- Veröffentlicht 23.09.2022 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:17:50
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumve...
CVE-2022-39225
- EPSS 0.21%
- Veröffentlicht 23.09.2022 07:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:49
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another user if the session object ID i...
CVE-2022-36079
- EPSS 0.6%
- Veröffentlicht 07.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:20
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Parse Server, prefixed by `_`) and protected fields (user defined) can be used as query constraints. Inte...
CVE-2022-31112
- EPSS 0.6%
- Veröffentlicht 30.06.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:55
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now r...