QID 982283
QID 982283: Nodejs (npm) Security Update for parse-server (GHSA-8w3j-g983-8jh5)
Versions of parse-server prior to 3.6.0 could allow an account enumeration attack via account linking.
`ParseError.ACCOUNT_ALREADY_LINKED(208)` was thrown BEFORE the AuthController checks the password and throws a `ParseError.SESSION_MISSING(206)` for Insufficient auth. An attacker can guess ids and get information about linked accounts/email addresses.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8w3j-g983-8jh5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8w3j-g983-8jh5 -
github.com/advisories/GHSA-8w3j-g983-8jh5
CVEs related to QID 982283
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8w3j-g983-8jh5 | parse-server |
|