CVE-2021-47986: Parse Server - Unreviewed Code Execution via Malicious Version Tags
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Parse Serverto a version that resolves this vulnerability.Fixed in 4.10.0 - Compensating control
Ensure dependency declarations do not specify affected Parse Server version tags that could resolve to unreviewed/personal-fork code.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47986?
The severity of CVE-2021-47986 is rated high with a score of 7.7.
How do I fix CVE-2021-47986?
To fix CVE-2021-47986, upgrade to Parse Server version 4.10.0 or later.
What type of vulnerability is CVE-2021-47986?
CVE-2021-47986 is a supply chain vulnerability allowing code execution via malicious version tags.
What impact does CVE-2021-47986 have on Parse Server?
CVE-2021-47986 allows attackers to execute unreviewed code by specifying affected version tags.
Which versions of Parse Server are affected by CVE-2021-47986?
CVE-2021-47986 affects all versions of Parse Server prior to 4.10.0.