Parse Server
Parse-Community · 4 CVEs
CVE-2024-47183
HIGH
Parse Server's custom object ID allows to acquire role privileges
Oct 4, 2024
CVE-2024-39309
CRITICAL
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
Jul 1, 2024
CVE-2024-29027
CRITICAL
Parse Server crash and RCE via invalid Cloud Function or Cloud Job name
Mar 19, 2024
CVE-2023-46119
HIGH
Parse Server may crash when uploading file without extension
Oct 25, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-47183 | Parse Server's custom object ID allows to acquire role privileges | HIGH | 0.42% | Oct 4, 2024 |
| CVE-2024-39309 | ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability | CRITICAL | 20.17% | Jul 1, 2024 |
| CVE-2024-29027 | Parse Server crash and RCE via invalid Cloud Function or Cloud Job name | CRITICAL | 1.19% | Mar 19, 2024 |
| CVE-2023-46119 | Parse Server may crash when uploading file without extension | HIGH | 1.05% | Oct 25, 2023 |
Showing 1 to 4 of 4 CVEs