GHSA-mxhg-rvwx-x993

Suggest an improvement
Source
https://github.com/advisories/GHSA-mxhg-rvwx-x993
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-mxhg-rvwx-x993/GHSA-mxhg-rvwx-x993.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mxhg-rvwx-x993
Aliases
Related
Published
2023-05-22T19:50:04Z
Modified
2023-11-08T04:12:35.752455Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Invalid push request payload crashes Parse Server
Details

Impact

The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload.

Patches

Invalid push notification payload is caught and an logged.

Workarounds

n/a

References

  • https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993
  • https://github.com/parse-community/parse-server-push-adapter/pull/217
Database specific
{
    "nvd_published_at": "2023-05-27T04:15:25Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-05-22T19:50:04Z"
}
References

Affected packages

npm / parse-server-push-adapter

Package

Name
parse-server-push-adapter
View open source insights on deps.dev
Purl
pkg:npm/parse-server-push-adapter

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.3