Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escaping of sub-field values in dot-notation queries. The vulnerability may also affect queries that use dot-notation field names with the distinct and where query parameters. This vulnerability only affects deployments using a PostgreSQL database. This vulnerability is fixed in 9.6.0-alpha.2 and 8.6.28.
An attacker can exploit field names in dot-notation format combined with the sort query parameter to inject malicious SQL code into the PostgreSQL database. The error results from improper escaping of sub-field values in dot-notation queries. The vulnerability may also affect queries using dot-notation with distinct and where parameters. The issue affects only installations using PostgreSQL database.
An attacker can conduct a SQL injection attack, which depending on the database configuration may lead to unauthorized reading, modification, or deletion of data stored in the PostgreSQL database.
Parse Server should be updated to version 8.6.28 or 9.6.0-alpha.2. Patches are available in the project's GitHub repository: https://github.com/parse-community/parse-server/releases/tag/8.6.28 and https://github.com/parse-community/parse-server/releases/tag/9.6.0-alpha.2. As a temporary workaround, consider switching to another supported database or restricting API access.
Parse Server (parse-community/parse-server) in versions earlier than 8.6.28 and earlier than 9.6.0-alpha.2, exclusively in configurations using PostgreSQL database.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XParseplatform Parse Server
APPParseplatform9.6.0< 8.6.289.0.0 – 9.6.0 (excl.)
Related vulnerabilities
Parse Server: obejście walidatorów Cloud Functions przez prototype chain
Race condition w Parse Server — błędna walidacja tokenów OAuth2
Parse Server — przejęcie konta przez manipulację zapytaniem (Auth Bypass)
SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach
SQL Injection w Parse Server (PostgreSQL) — operacje Increment na polach zagnieżdżonych