Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This issue is patched in version 5.3.1 and in 4.10.18. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-11-10T00:00:00
Updated: 2024-08-03T12:07:41.973Z
Reserved: 2022-09-02T00:00:00
Link: CVE-2022-39396
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-11-10T01:15:10.253
Modified: 2022-11-11T02:01:41.257
Link: CVE-2022-39396
Redhat
No data.