ZDI-CAN-23894: ZDI-24-896: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Parse Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-39309.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23894?
ZDI-CAN-23894 has been assigned a CVSS rating of 9.8, indicating critical severity.
How do I fix ZDI-CAN-23894?
To address ZDI-CAN-23894, upgrade to the latest version of Parse Server where the vulnerability has been patched.
What does ZDI-CAN-23894 affect?
ZDI-CAN-23894 affects installations of Parse Server that are vulnerable to authentication bypass.
Can ZDI-CAN-23894 be exploited without authentication?
Yes, ZDI-CAN-23894 can be exploited by remote attackers without requiring authentication.
Is there a workaround for ZDI-CAN-23894?
Currently, no specific workarounds are provided for ZDI-CAN-23894 other than upgrading to a fixed version.