Junglewise Threat Intelligence

CVE-2020-5251: Parse Server NoSQL regex injection information disclosure

CVE-2020-5251 · Severity: low · CVSS 3.1 · Published 2020-03-04

Technologies: Parse Community Parse-Server, parse-server (npm). Vendors: Parse Community, npm.

Executive brief

Parse Server is a backend-as-a-service framework that manages user accounts and authentication. An attacker with network access can exploit NoSQL regex injection to enumerate valid user accounts and potentially hijack email verification or password reset processes by brute-forcing security tokens through pattern matching. This allows unauthorized access to sensitive account information and account takeover without legitimate user interaction.

Technical details

The vulnerability is a NoSQL regex injection flaw in Parse Server's query processing, affecting authentication and account recovery endpoints. Attackers can inject regex patterns (e.g., "$regex") into NoSQL query parameters like sessionToken, email verification tokens, and password reset tokens to bypass input validation and match arbitrary data. The attack is network-accessible and requires only basic authentication (application ID and key), no user interaction. By iteratively refining regex patterns, an attacker can enumerate valid session tokens, enumerate registered user accounts, verify email addresses on accounts they don't own, and reset passwords for other users. The vulnerability is fixed in version 4.1.0; all versions 4.0.0 and earlier are affected.

Affected products

  • Parse Community parse-server <= 4.0.0

Timeline

  • 2020-03-04: disclosed
  • 2020-03-04: patched: Fix released in version 4.1.0

References

Related threats