Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.
History

Wed, 13 Nov 2024 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Parseplatform
Parseplatform parse Server
Weaknesses CWE-863
CPEs cpe:2.3:a:parseplatform:parse_server:*:*:*:*:*:*:*:*
Vendors & Products Parseplatform
Parseplatform parse Server

Fri, 04 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Parse Community
Parse Community parse Server
CPEs cpe:2.3:a:parse_community:parse_server:*:*:*:*:*:*:*:*
Vendors & Products Parse Community
Parse Community parse Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Title Parse Server has user id/role name confusion with ACLs Parse Server's custom object ID allows to acquire role privileges

Fri, 04 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Description Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.
Title Parse Server has user id/role name confusion with ACLs
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-04T15:06:45.274Z

Updated: 2024-10-04T15:30:37.224Z

Reserved: 2024-09-19T22:32:11.963Z

Link: CVE-2024-47183

cve-icon Vulnrichment

Updated: 2024-10-04T15:28:04.995Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T15:15:13.010

Modified: 2024-11-13T21:15:50.743

Link: CVE-2024-47183

cve-icon Redhat

No data.