HIGH
Parse Server crashes when receiving file download request with invalid byte range
Published Oct 24, 2022
7.5
HIGHCVSS 3.1
EPSS 0.75%
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no known workarounds.
Affected products
-
- Version < 4.10.17StatusaffectedConstraints-
- Version >= 5.0.0, < 5.2.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Parse-Community | Parse-Server | n/a |
|
OR
- < 4.10.17
- ≥ 5.0.0 · < 5.2.8
No data.
No Red Hat product state for this CVE.
parse-server
npm
Introduced 0 Fixed 4.10.17parse-server
npm
Introduced 5.0.0 Fixed 5.2.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | parse-server | 0 | 4.10.17 |
| npm | parse-server | 5.0.0 | 5.2.8 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7100 Advisory
- https://github.com/advisories/GHSA-h423-w6qv-2wj3 Advisory
- https://github.com/parse-community/parse-server/commit/066f29673ab4030b6b5b90c0c0326f7d3fe7612a
- https://github.com/parse-community/parse-server/commit/3d7a61ecd5231638f01ff1a965b6313043c594a7
- https://github.com/parse-community/parse-server/releases/tag/4.10.17
- https://github.com/parse-community/parse-server/security/advisories/GHSA-h423-w6qv-2wj3 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-39313
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 24, 2022
Updated Apr 23, 2025
Reserved Sep 2, 2022
Link CVE-2022-39313
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-7100 GHSA-H423-W6QV-2WJ3 Assigner GitHub_M
Published Oct 24, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-7100