First published: Wed May 04 2022(Updated: )
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Parseplatform Parse-server | <4.10.10 | |
Parseplatform Parse-server | >=5.0.0<5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24901 is a vulnerability that allows attackers to bypass authentication in the Apple Game Center authentication adapter, potentially leading to DoS attacks.
Attackers can exploit CVE-2022-24901 by exploiting the improper validation of the Apple certificate URL in the Apple Game Center authentication adapter.
CVE-2022-24901 has a severity level of 7.5 (high).
To fix CVE-2022-24901, update Parseplatform Parse-server to version 5.2.1 or apply the necessary patches provided by the vendor.
You can find more information about CVE-2022-24901 at the following reference: https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr