Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The sub-key name is interpolated directly into SQL string literals without escaping. An attacker who can send write requests to the Parse Server REST API can inject arbitrary SQL via a crafted sub-key name containing single quotes, potentially executing commands or reading data from the database, bypassing CLPs and ACLs. Only Postgres deployments are affected. This vulnerability is fixed in 9.6.0-alpha.5 and 8.6.31.
The vulnerability results from direct interpolation of the subkey name (e.g., the fragment after a dot in expressions like stats.counter) into SQL query strings without prior escaping. An attacker who has the ability to send write requests to the Parse Server REST API can place a single quote or other special SQL character in the subkey name, causing the input to be interpreted as SQL code. This allows execution of arbitrary commands on the database or reading its contents, bypassing Class Level Permissions (CLP) and Access Control Lists (ACL) mechanisms.
An attacker can execute arbitrary SQL queries on the PostgreSQL database, gaining unauthorized access to stored data or modifying it, completely bypassing configured CLP and ACL rules.
Parse Server must be updated to version 8.6.31 (stable branch) or 9.6.0-alpha.5 (alpha branch). Patches are available in the project's official GitHub repository. Deployments using adapters other than PostgreSQL are not vulnerable.
Parse Server (Parseplatform parse-server) in versions earlier than 8.6.31 (8.x branch) and earlier than 9.6.0-alpha.5 (9.x branch), only when using the PostgreSQL adapter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XParseplatform Parse Server
APPParseplatform9.6.0< 8.6.319.0.0 – 9.6.0 (excl.)
Related vulnerabilities
Parse Server: obejście walidatorów Cloud Functions przez prototype chain
Race condition w Parse Server — błędna walidacja tokenów OAuth2
Parse Server — przejęcie konta przez manipulację zapytaniem (Auth Bypass)
SQL Injection w Parse Server poprzez dot-notation i parametr sort (PostgreSQL)
SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach