CVE-2021-39187
Summary
| CVE | CVE-2021-39187 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-02 16:15:00 UTC |
| Updated | 2022-08-05 10:51:00 UTC |
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch. There is a patch for this issue in version 4.10.3. No workarounds aside from upgrading are known to exist. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Merge pull request from GHSA-xqp8-w826-hh6x · parse-community/parse-server@308668c · GitHub |
MISC |
github.com |
|
| Release 4.10.3 · parse-community/parse-server · GitHub |
MISC |
github.com |
|
| [NODE-3463] Cannot catch exception with useUnifiedTopology - MongoDB Jira |
MISC |
jira.mongodb.org |
|
| Server crashes with invalid explain query parameter · Advisory · parse-community/parse-server · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981055 Nodejs (npm) Security Update for parse-server (GHSA-xqp8-w826-hh6x)