Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication requests for different OAuth2 providers, one provider's token validation may execute using another provider's configuration, potentially allowing a token that should be rejected by one provider to be accepted because it is validated against a different provider's policy. Deployments that configure multiple OAuth2 providers via the oauth2: true flag are affected. This vulnerability is fixed in 9.6.0-alpha.11 and 8.6.37.
The built-in OAuth2 adapter in Parse Server exports a single instance (singleton) that is shared by all OAuth2 provider configurations. When authentication requests for different OAuth2 providers arrive at the server simultaneously, a situation may occur where token validation for one provider is performed using the configuration (policy) of another provider. As a result, a token that should be rejected by the correct provider may be incorrectly accepted — because it is verified against another provider's policy. The vulnerability affects only deployments using multiple OAuth2 providers configured with the oauth2: true flag.
An attacker can gain unauthorized access to a user account or resources protected by Parse Server using an OAuth2 token that would normally be rejected. This results in a breach of data confidentiality and integrity.
Parse Server should be updated to version 8.6.37 (stable branch) or 9.6.0-alpha.11 (alpha branch). Patches are available in the vendor references on GitHub. If immediate updates are not possible, consider limiting the number of concurrent authentication requests or temporarily disabling support for multiple OAuth2 providers.
Parse Server (Parseplatform parse-server) in versions prior to 8.6.37 and prior to 9.6.0-alpha.11, with the vulnerability being active only in a configuration with multiple OAuth2 providers (oauth2: true flag).
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XParseplatform Parse Server
APPParseplatform9.6.0< 8.6.379.0.0 – 9.6.0 (excl.)
Related vulnerabilities
Parse Server: obejście walidatorów Cloud Functions przez prototype chain
Parse Server — przejęcie konta przez manipulację zapytaniem (Auth Bypass)
SQL Injection w Parse Server poprzez dot-notation i parametr sort (PostgreSQL)
SQL Injection w Parse Server (PostgreSQL) — operacje Increment na polach zagnieżdżonych
SQL Injection w Parse Server (PostgreSQL) — operacje Increment na zagnieżdżonych polach