HIGH🇵🇱 Wersja polska

CVE-2022-31112

CVSS 8.2v3.1pub. 2022-06-30upd. 2024-11-21

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now removes protected fields from the client response. Users are advised to upgrade. Users unable t upgrade should use `Parse.Cloud.afterLiveQueryEvent` to manually remove protected fields.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  • Parseplatform Parse Server

    APP
    Parseplatform
    < 4.10.135.0.0 – 5.2.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34532CRITICAL9.1PL ✓same product

Parse Server: obejście walidatorów Cloud Functions przez prototype chain

CVE-2026-32248CRITICAL9.3PL ✓same product

Parse Server — przejęcie konta przez manipulację zapytaniem (Auth Bypass)

CVE-2026-32242CRITICAL9.1PL ✓same product

Race condition w Parse Server — błędna walidacja tokenów OAuth2

CVE-2026-31856CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach

CVE-2026-31871CRITICAL9.3PL ✓same product

SQL Injection w Parse Server (PostgreSQL) — operacje Increment na polach zagnieżdżonych