CVE-2022-24901

HIGH

parse-server < 4.10.10 - Improper Certificate Validation in Apple Game Center Authentication

Title source: llm
STIX 2.1

Description

Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295 CWE-287
Status published
Products (2)
npm/parse-server 0 - 4.10.10npm
parseplatform/parse-server < 4.10.10
Published May 04, 2022
Tracked Since Feb 18, 2026