Junglewise Threat Intelligence

CVE-2019-1020013: parse-server account enumeration in account linking

CVE-2019-1020013 · Severity: low · CVSS 3 · Published 2019-07-11

Technologies: Parse Community Parse-Server, parse-server (npm). Vendors: Parse Community, npm.

Executive brief

Parse Server is a backend framework used to build applications with user accounts and linked authentication methods. A flaw in the account linking mechanism allowed attackers to enumerate user accounts and discover email addresses by triggering specific error messages, without requiring valid credentials. This could help attackers identify valid accounts for targeted attacks.

Technical details

The vulnerability is an information disclosure/account enumeration flaw (CWE-209) in parse-server versions prior to 3.6.0. The AuthController threw a ParseError.ACCOUNT_ALREADY_LINKED(208) error before validating the user's password, revealing whether an account was linked to a given identifier. An attacker with network access could enumerate user accounts and linked email addresses by guessing IDs and observing error responses. No authentication or user interaction is required. The vulnerability was patched in version 3.6.0 via commit 73b0f9a, which reordered validation to check authentication before reporting account link status.

Affected products

  • parse-community parse-server < 3.6.0

Timeline

  • 2019-07-11: disclosed
  • 2019-07-11: patched: Fixed in version 3.6.0

References

Related threats