CVE-2021-39187
Crash server with query parameter
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch. There is a patch for this issue in version 4.10.3. No workarounds aside from upgrading are known to exist.
Parse Server es un backend de código abierto que puede ser desplegado en cualquier infraestructura que pueda ejecutar Node.js. En las versiones anteriores a 4.10.3, Parse Server se bloquea cuando una petición de consulta contiene un valor no válido para la opción "explain". Esto es debido a un bug en el controlador Node.js de MongoDB que lanza una excepción que Parse Server no puede atrapar. Se presenta un parche para este problema en versión 4.10.3. No se conocen soluciones aparte de la actualización
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-16 CVE Reserved
- 2021-09-02 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/parse-community/parse-server/releases/tag/4.10.3 | Third Party Advisory | |
https://github.com/parse-community/parse-server/security/advisories/GHSA-xqp8-w826-hh6x | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/parse-community/parse-server/commit/308668c89474223e2448be92d6823b52c1c313ec | 2022-08-05 | |
https://jira.mongodb.org/browse/NODE-3463 | 2022-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Parseplatform Search vendor "Parseplatform" | Parse-server Search vendor "Parseplatform" for product "Parse-server" | < 4.10.3 Search vendor "Parseplatform" for product "Parse-server" and version " < 4.10.3" | node.js |
Affected
|