Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-10-22T21:25:16
Updated: 2024-08-04T13:15:19.922Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15270
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-10-22T22:15:12.063
Modified: 2024-11-21T05:05:14.230
Link: CVE-2020-15270
Redhat
No data.