CVE-2020-5251
HIGHParseplatform Parse-server < 4.1.0 - Incorrect Authorization
Title source: ruleDescription
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/parse-community/parse-server/security/advisories/GHSA-h4mf-75hf-67w4
Patch, Third Party Advisory x_refsource_misc
https://github.com/parse-community/parse-server/commit/3a3a5eee5ffa48da1352423312cb767de14de269
Scores
CVSS v3
7.7
EPSS
0.0031
EPSS Percentile
54.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Details
CWE
CWE-285
CWE-863
Status
published
Products (2)
npm/parse-server
0 - 4.1.0npm
parseplatform/parse-server
< 4.1.0
Published
Mar 04, 2020
Tracked Since
Feb 18, 2026