QID 981442
QID 981442: Nodejs (npm) Security Update for parse-server (GHSA-2479-qvv7-47qq)
Versions of `parse-server` prior to 3.4.1 are vulnerable to Denial of Service (DoS). POST requests to `/parse/classes/_Audience` (or other volatile classes) cause the server to respond with a `500 Internal Server Error` for any subsequent POST requests.
## Recommendation
Upgrade to version 3.4.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2479-qvv7-47qq for updates pertaining to this vulnerability.
Vendor References
- GHSA-2479-qvv7-47qq -
github.com/advisories/GHSA-2479-qvv7-47qq
CVEs related to QID 981442
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2479-qvv7-47qq | parse-server |
|