Description
Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.
Scores
CVSS v3
4.3
EPSS
0.0025
EPSS Percentile
48.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-672
Status
published
Products (2)
npm/parse-server
0 - 4.4.0npm
parseplatform/parse-server
< 4.3.0
Published
Oct 22, 2020
Tracked Since
Feb 18, 2026