CVE-2022-31112
Summary
| CVE | CVE-2022-31112 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-30 17:15:00 UTC |
| Updated | 2023-07-24 13:17:00 UTC |
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now removes protected fields from the client response. Users are advised to upgrade. Users unable t upgrade should use `Parse.Cloud.afterLiveQueryEvent` to manually remove protected fields. |
Risk And Classification
Problem Types: CWE-212
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Parseplatform | Parse-server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: protected fields exposed via LiveQuery (GHSA-crrq-vr9j-fxxh) by mtrezza · Pull Request #8073 · parse-community/parse-server · GitHub | MISC | github.com | |
| Protected fields exposed via LiveQuery · Advisory · parse-community/parse-server · GitHub | CONFIRM | github.com | |
| fix: protected fields exposed via LiveQuery (GHSA-crrq-vr9j-fxxh) [sk… · parse-community/parse-server@9fd4516 · GitHub | MISC | github.com | |
| Release 5.2.4 · parse-community/parse-server · GitHub | MISC | github.com | |
| fix: protected fields exposed via LiveQuery (GHSA-crrq-vr9j-fxxh) by mtrezza · Pull Request #8074 · parse-community/parse-server · GitHub | MISC | github.com | |
| fix: protected fields exposed via LiveQuery; this removes protected f… · parse-community/parse-server@309f64c · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.