First published: Tue Oct 24 2023(Updated: )
### Impact Parse Server crashes when uploading a file without extension. ### Patches A permanent fix has been implemented to prevent the server from crashing. ### Workarounds There are no known workarounds. ### References - GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-792q-q67h-w579 - Patched in Parse Server 6: https://github.com/parse-community/parse-server/releases/tag/6.3.1 - Patched in Parse Server 5 (LTS): https://github.com/parse-community/parse-server/releases/tag/5.5.6
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Parseplatform Parse-server | >=1.0.0<5.5.6 | |
Parseplatform Parse-server | >=6.0.0<6.3.1 | |
npm/parse-server | >=6.0.0<6.3.1 | 6.3.1 |
npm/parse-server | >=1.0.0<5.5.6 | 5.5.6 |
>=1.0.0<5.5.6 | ||
>=6.0.0<6.3.1 |
https://github.com/parse-community/parse-server/commit/686a9f282dc23c31beab3d93e6d21ccd0e1328fe
https://github.com/parse-community/parse-server/commit/fd86278919556d3682e7e2c856dfccd5beffbfc0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Parse Server crashes when uploading a file without extension.
A permanent fix has been implemented in version 6.3.1 of parse-server.
There are no known workarounds.
You can find more information about CVE-2023-46119 in the GitHub security advisory.