GHSA-prm5-8g2m-24gg

Suggest an improvement
Source
https://github.com/advisories/GHSA-prm5-8g2m-24gg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-prm5-8g2m-24gg/GHSA-prm5-8g2m-24gg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-prm5-8g2m-24gg
Aliases
Related
Published
2022-11-08T17:29:16Z
Modified
2023-12-06T01:02:33.974497Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Remote code execution via MongoDB BSON parser through prototype pollution
Details

Impact

An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.

Patches

Prevent prototype pollution in MongoDB database adapter.

Workarounds

Disable remote code execution through the MongoDB BSON parser.

Collaborators

Mikhail Shcherbakov (KTH), Cristian-Alexandru Staicu (CISPA) and Musard Balliu (KTH) working with Trend Micro Zero Day Initiative

References

  • https://github.com/parse-community/parse-server/security/advisories/GHSA-prm5-8g2m-24gg
Database specific
{
    "nvd_published_at": "2022-11-10T01:15:00Z",
    "cwe_ids": [
        "CWE-1321"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2022-11-08T17:29:16Z"
}
References

Affected packages

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.10.18

npm / parse-server

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.3.1