QID 982283

QID 982283: Nodejs (npm) Security Update for parse-server (GHSA-8w3j-g983-8jh5)

Versions of parse-server prior to 3.6.0 could allow an account enumeration attack via account linking.
`ParseError.ACCOUNT_ALREADY_LINKED(208)` was thrown BEFORE the AuthController checks the password and throws a `ParseError.SESSION_MISSING(206)` for Insufficient auth. An attacker can guess ids and get information about linked accounts/email addresses.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-8w3j-g983-8jh5 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982283

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8w3j-g983-8jh5 parse-server URL Logo github.com/advisories/GHSA-8w3j-g983-8jh5