CVE-2022-41878
published 2022-11-10CVE-2022-41878: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
54.4th percentile
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the `requestKeywordDenylist` option. This issue is fixed in versions 4.10.19, and 5.3.2. If upgrade is not possible, the following Workarounds may be applied: Configure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parse-community | parse-server | < 4.10.19 | 4.10.19 |
| parse-community | parse-server | >= 0 < 4.10.19 | 4.10.19 |
| parse-community | parse-server | >= 5.0.0 < 5.3.2 | 5.3.2 |
| parseplatform | parse-server | < 4.10.19 | 4.10.19 |
| parseplatform | parse-server | >= 5.0.0 < 5.3.2 | 5.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
osv·2022-11-09
CVE-2022-41878 [HIGH] Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
### Impact
Keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the `requestKeywordDenylist` option.
### Patches
Improved keyword detection.
### Workarounds
Configure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature.
### Collaborators
Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative
### References
- https://github.com/parse-community/parse-server/security/advisories
GHSA
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
ghsa·2022-11-09
CVE-2022-41878 [HIGH] CWE-1321 Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers
### Impact
Keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the `requestKeywordDenylist` option.
### Patches
Improved keyword detection.
### Workarounds
Configure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature.
### Collaborators
Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative
### References
- https://github.com/parse-community/parse-server/security/advisories
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-10
Published