GHSA-xw6g-jjvf-wwf9

Suggest an improvement
Source
https://github.com/advisories/GHSA-xw6g-jjvf-wwf9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-xw6g-jjvf-wwf9/GHSA-xw6g-jjvf-wwf9.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-xw6g-jjvf-wwf9
Aliases
Related
Published
2022-06-20T22:25:46Z
Modified
2023-12-06T00:47:16.226635Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Invalid file request can crash server
Details

Impact

Certain types of invalid files requests are not handled properly and can crash the server. If you are running multiple Parse Server instances in a cluster, the availability impact may be low; if you are running Parse Server as a single instance without redundancy, the availability impact may be high.

Patches

To prevent this, invalid requests are now properly handled.

Workarounds

None

References

  • https://github.com/parse-community/parse-server/security/advisories/GHSA-xw6g-jjvf-wwf9
  • https://github.com/parse-community/parse-server

For more information

Database specific
{
    "nvd_published_at": "2022-06-27T21:15:00Z",
    "github_reviewed_at": "2022-06-20T22:25:46Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-252"
    ]
}
References

Affected packages

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.10.12

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.2.3