Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1402 | Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched. |
Github GHSA |
GHSA-2xm2-xj2q-qgpj | receiving subscription objects with deleted session |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:15:19.922Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15270
No data.
Status : Modified
Published: 2020-10-22T22:15:12.063
Modified: 2024-11-21T05:05:14.230
Link: CVE-2020-15270
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA