ZDI-24-896: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Parse Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-39309.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-896?
The severity of ZDI-24-896 is rated 9.8 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-24-896?
To fix ZDI-24-896, ensure that you update to the latest version of Parse Server that addresses this authentication bypass vulnerability.
What type of attack does ZDI-24-896 enable?
ZDI-24-896 allows remote attackers to exploit authentication bypass vulnerabilities on affected Parse Server installations.
Is authentication required to exploit ZDI-24-896?
No, authentication is not required to exploit the ZDI-24-896 vulnerability.
What products are affected by ZDI-24-896?
Parse Server installations are affected by the ZDI-24-896 vulnerability.