First published: Mon Jul 29 2019(Updated: )
parse-server before 3.6.0 allows account enumeration.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Parseplatform Parse-server | <3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1020013 is a vulnerability in parse-server before version 3.6.0 that allows for account enumeration.
CVE-2019-1020013 is rated as medium severity with a CVSS score of 5.3.
CVE-2019-1020013 affects parse-server versions up to (exclusive) 3.6.0.
To fix CVE-2019-1020013, you need to update parse-server to version 3.6.0 or higher.
More information about CVE-2019-1020013 can be found at the following reference link: [GitHub Advisory](https://github.com/parse-community/parse-server/security/advisories/GHSA-8w3j-g983-8jh5)