First published: Mon May 22 2023(Updated: )
### Impact The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload. ### Patches Invalid push notification payload is caught and an logged. ### Workarounds n/a ### References - https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993 - https://github.com/parse-community/parse-server-push-adapter/pull/217
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Parseplatform Parse Server Push Adapter | <4.1.3 | |
npm/parse-server-push-adapter | <4.1.3 | 4.1.3 |
https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload.
Update to version 4.1.3 of the parse-server-push-adapter package.
No, there are no workarounds available.
You can find more information about CVE-2023-32688 at the following references: - [GitHub Advisory](https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993) - [GitHub Pull Request](https://github.com/parse-community/parse-server-push-adapter/pull/217) - [GitHub Release](https://github.com/parse-community/parse-server-push-adapter/releases/tag/4.1.3)