Junglewise Threat Intelligence

CVE-2021-39187: Parse Server denial of service with invalid explain parameter

CVE-2021-39187 · Severity: low · CVSS 3.1 · Published 2021-09-02

Technologies: Parse Community Parse Server, parse-server (npm). Vendors: Parse Community, npm.

Executive brief

Parse Server is a popular backend-as-a-service platform that handles application data and queries. When a database query includes an invalid value for the explain option, the server crashes due to an unhandled exception in the MongoDB driver, causing service outages and disrupting user access to the application.

Technical details

This is a denial-of-service vulnerability (CWE-20, CWE-74, CWE-755) caused by improper input validation of the explain query parameter. When a network request contains an invalid explain option value, the MongoDB Node.js driver throws an uncaught exception that Parse Server cannot handle, resulting in immediate server termination. No authentication or user interaction is required—any unauthenticated attacker with network access can send a malicious query to trigger the crash. The vulnerability affects all versions prior to 4.10.3, which includes proper exception handling to prevent the crash.

Affected products

  • Parse Community Parse Server < 4.10.3

Timeline

  • 2021-09-02: disclosed
  • 2021-09-02: patched: Parse Server 4.10.3 released

References

Related threats