ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
Critical severity
GitHub Reviewed
Published
Mar 1, 2024
in
parse-community/parse-server
•
Updated Mar 1, 2024
Package
Affected versions
< 6.5.0
>= 7.0.0-alpha.1, < 7.0.0-alpha.20
Patched versions
6.5.0
7.0.0-alpha.20
Description
Published by the National Vulnerability Database
Mar 1, 2024
Published to the GitHub Advisory Database
Mar 1, 2024
Reviewed
Mar 1, 2024
Last updated
Mar 1, 2024
Impact
This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database.
Patches
The algorithm to detect SQL injection has been improved.
Workarounds
None.
References
Credits
References