Executive brief
Parse Server is a popular backend-as-a-service platform that handles application data and queries. When a database query includes an invalid value for the explain option, the server crashes due to an unhandled exception in the MongoDB driver, causing service outages and disrupting user access to the application.
Technical details
This is a denial-of-service vulnerability (CWE-20, CWE-74, CWE-755) caused by improper input validation of the explain query parameter. When a network request contains an invalid explain option value, the MongoDB Node.js driver throws an uncaught exception that Parse Server cannot handle, resulting in immediate server termination. No authentication or user interaction is required—any unauthenticated attacker with network access can send a malicious query to trigger the crash. The vulnerability affects all versions prior to 4.10.3, which includes proper exception handling to prevent the crash.
Affected products
- Parse Community Parse Server < 4.10.3
Timeline
- 2021-09-02: disclosed
- 2021-09-02: patched: Parse Server 4.10.3 released