For regular (non-LiveQuery) queries, the session token is removed from the response, but for LiveQuery payloads it is currently not. If a user has a LiveQuery subscription on the Parse.User
class, all session tokens created during user sign-ups will be broadcast as part of the LiveQuery payload.
Remove session token from LiveQuery payload.
Set user.acl(new Parse.ACL())
in a beforeSave trigger to make the user private already on sign-up.
{ "nvd_published_at": "2021-09-30T15:15:00Z", "github_reviewed_at": "2021-09-30T16:43:12Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-200" ] }