HIGH
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
Published May 4, 2022
7.5
HIGHCVSS 3.1
EPSS 0.69%
Description
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
Affected products
-
- Version < 4.10.10StatusaffectedConstraints-
- Version >= 5.0.0, < 5.2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Parse-Community | Parse-Server | n/a |
|
OR
- < 4.10.10
- ≥ 5.0.0 · < 5.2.1
No data.
No Red Hat product state for this CVE.
parse-server
npm
Introduced 0 Fixed 4.10.10parse-server
npm
Introduced 5.0.0 Fixed 5.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | parse-server | 0 | 4.10.10 |
| npm | parse-server | 5.0.0 | 5.2.1 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4956 Advisory
- https://github.com/advisories/GHSA-qf8x-vqjv-92gr Advisory
- https://github.com/parse-community/parse-server/commit/af4a0417a9f3c1e99b3793806b4b18e04d9fa999
- https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24901
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4956 | Advisory | |
| https://github.com/advisories/GHSA-qf8x-vqjv-92gr | Advisory | |
| https://github.com/parse-community/parse-server/commit/af4a0417a9f3c1e99b3793806b4b18e04d9fa999 | ||
| https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-24901 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 4, 2022
Updated Apr 23, 2025
Reserved Feb 10, 2022
Link CVE-2022-24901
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-4956 GHSA-QF8X-VQJV-92GR Assigner GitHub_M
Published May 4, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-4956