CVE-2022-41879: Parse Server subject to Prototype pollution via Cloud Code Webhooks
Impact
A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server requestKeywordDenylist option.
Patches
Improved keyword detection.
Workarounds
None.
Collaborators
Mikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative
References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-93vw-8fm5-p2jf
Other sources
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to use prototype pollution to bypass the Parse Server requestKeywordDenylist option. This issue has been patched in versions 5.3.3 and 4.10.20. There are no known workarounds.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/parse-serverto a version that resolves this vulnerability.Fixed in 5.3.3 - Upgrade
Upgrade
npm/parse-serverto a version that resolves this vulnerability.Fixed in 4.10.20 - Upgrade
Upgrade
Parse Serverto a version that resolves this vulnerability.Fixed in 5.3.3 - Upgrade
Upgrade
Parse Serverto a version that resolves this vulnerability.Fixed in 4.10.20
Event History
Frequently Asked Questions
What is the impact of CVE-2022-41879?
A compromised Parse Server Cloud Code Webhook target endpoint allows an attacker to bypass the Parse Server `requestKeywordDenylist` option using prototype pollution.
How can the vulnerability be patched?
The vulnerability can be patched by implementing improved keyword detection in the affected software.
Are there any workarounds for CVE-2022-41879?
No, there are no known workarounds for this vulnerability.
What is the severity of CVE-2022-41879?
CVE-2022-41879 has a severity rating of high (7.2).
Which versions of parse-server are affected by CVE-2022-41879?
Versions 4.10.20 (inclusive) to 5.3.3 (exclusive) of parse-server are affected by CVE-2022-41879.