Executive brief
Parse Server is a Node.js backend-as-a-service platform used by developers to build and run applications. Malicious version tags were pushed to the Parse Server repository pointing to unreviewed code in a contributor's personal fork, potentially containing compromised or buggy functionality. Applications depending on these specific version tags may have unknowingly executed unvetted code, creating a risk of service disruption, data breach, or deployment of broken features.
Technical details
This vulnerability involves a repository integrity attack where 34 version tags (ranging from 4.0.0-beta1 through 4.9.3) were maliciously created to reference a personal fork of a Parse Server contributor who had write access to the main repository. The unreviewed code at these tags has not been vetted by the Parse Platform maintainers. While no official npm releases were published with these tags, developers could reference them directly via git URLs (e.g., "parse-server": "git@github.com:parse-community/parse-server.git#4.9.3"), causing any code at those tags to be executed in their environments. Additionally, the Bitnami Docker image platform picked up the corrupted tag 4.9.3 and published it in their Parse Server image. The root cause was insufficient access controls or monitoring on the repository. There is no indication of malicious code injection, but the possibility of security vulnerabilities and broken functionality cannot be ruled out. The fix is to upgrade to version 4.10.0 or later, or downgrade to the unaffected version 4.5.2.
Affected products
- Parse Community Parse Server 4.0.0-beta1 through 4.9.3 (34 affected versions); fixed in 4.10.0
Timeline
- 2021-09-03: disclosed: Advisory published by Parse Community
- 2021-07-21: other: Security incident first discovered by Parse Platform
- 2021-09-07: other: Advisory published on public sources (GHSA, OSV)
- 2021-09-03: patched: Fix available in version 4.10.0; tags deleted from repository