CVE-2023-46119: Parse Server may crash when uploading file without extension
Impact
Parse Server crashes when uploading a file without extension.
Patches
A permanent fix has been implemented to prevent the server from crashing.
Workarounds
There are no known workarounds.
References
- GitHub security advisory: https://github.com/parse-community/parse-server/security/advisories/GHSA-792q-q67h-w579 - Patched in Parse Server 6: https://github.com/parse-community/parse-server/releases/tag/6.3.1 - Patched in Parse Server 5 (LTS): https://github.com/parse-community/parse-server/releases/tag/5.5.6
Other sources
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the impact of CVE-2023-46119?
Parse Server crashes when uploading a file without extension.
What patches are available for CVE-2023-46119?
A permanent fix has been implemented in version 6.3.1 of parse-server.
Are there any workarounds for CVE-2023-46119?
There are no known workarounds.
Where can I find more information about CVE-2023-46119?
You can find more information about CVE-2023-46119 in the GitHub security advisory.