ZDI-23-1160: Parse Server transformUpdate Prototype Pollution Remote Code Execution Vulnerability
Published Aug 22, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Parse Server. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Parse Server
Event History
Aug 22, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1160?
ZDI-23-1160 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How can ZDI-23-1160 be exploited?
ZDI-23-1160 can be exploited by authenticated attackers to execute arbitrary code on affected Parse Server installations.
3
Which versions of Parse Server are affected by ZDI-23-1160?
ZDI-23-1160 affects all versions of Parse Server that have not applied the appropriate patches.
4
How do I fix ZDI-23-1160?
To fix ZDI-23-1160, update your Parse Server installation to the latest version provided by the vendor.
5
Is authentication required to exploit ZDI-23-1160?
Yes, authentication is required to exploit the ZDI-23-1160 vulnerability.