CVE-2022-39313: Parse Server crashes when receiving file download request with invalid byte range
Impact
Parse Server crashes when a file download request is received with an invalid byte range.
Patches
Improved parsing of the range parameter to properly handle invalid range requests.
Workarounds
None
References
- GHSA-h423-w6qv-2wj3
Other sources
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no known workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39313.
What is the impact of the vulnerability?
The vulnerability can cause Parse Server to crash, resulting in a Denial of Service.
Which versions of Parse Server are affected?
Versions prior to 4.10.17 and prior to 5.2.8 on the 5.x branch are affected.
How can the vulnerability be exploited?
The vulnerability can be exploited by sending a file download request with an invalid byte range.
What is the severity of CVE-2022-39313?
The severity of CVE-2022-39313 is high, with a CVSS score of 7.5.