{"api_version":"1","generated_at":"2026-07-23T20:58:22+00:00","cve":"CVE-2020-15126","urls":{"html":"https://cve.report/CVE-2020-15126","api":"https://cve.report/api/cve/CVE-2020-15126.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15126","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15126"},"summary":{"title":"CVE-2020-15126","description":"In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-07-22 23:15:00","updated_at":"2020-07-28 17:30:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa","name":"https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Merge pull request from GHSA-236h-rqv8-8q73 · parse-community/parse-server@78239ac · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73","name":"https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"GraphQL: Security breach on Viewer query · Advisory · parse-community/parse-server · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430","name":"https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"parse-server/CHANGELOG.md at master · parse-community/parse-server · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15126","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15126","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"parseplatform","cpe5":"parse_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15126","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"parseplatform","cpe5":"parse_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-15126","qid":"983190","title":"Nodejs (npm) Security Update for parse-server (GHSA-236h-rqv8-8q73)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-15126","STATE":"PUBLIC","TITLE":"Information disclosure through Viewer query in parse-server"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"parse-server","version":{"version_data":[{"version_value":">= 3.5.0, < 4.3.0"}]}}]},"vendor_name":"parse-community"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-863: Incorrect Authorization"}]}]},"references":{"reference_data":[{"name":"https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73","refsource":"CONFIRM","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73"},{"name":"https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa","refsource":"MISC","url":"https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa"},{"name":"https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430","refsource":"MISC","url":"https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430"}]},"source":{"advisory":"GHSA-236h-rqv8-8q73","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-07-22 23:15:00","lastModifiedDate":"2020-07-28 17:30:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:parseplatform:parse_server:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndExcluding":"4.3.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15126","Ordinal":"176505","Title":"CVE-2020-15126","CVE":"CVE-2020-15126","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15126","Ordinal":"1","NoteData":"In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15126","Ordinal":"2","NoteData":"2020-07-22","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15126","Ordinal":"3","NoteData":"2020-07-22","Type":"Other","Title":"Modified"}]}}}