Junglewise Threat Intelligence

CVE-2022-24901: Parse Server authentication bypass and DoS in Apple Game Center adapter

CVE-2022-24901 · Severity: low · CVSS 3.1 · Published 2022-05-04

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a backend framework that allows developers to deploy an API for mobile and web applications. Its Apple Game Center authentication adapter contains weak validation of certificate URLs, allowing an attacker to bypass authentication checks or cause the server to become unavailable by downloading malicious or oversized resources.

Technical details

The vulnerability stems from weak URL validation in the Apple Game Center authentication adapter when processing Apple certificate URLs. An attacker can manipulate the certificate URL parameter to bypass authentication (CWE-287) or to point to malicious resources, leading to denial of service. The attack requires no authentication or special network access—a remote, unauthenticated user can craft a malicious request. The vulnerability allows certificate URL spoofing and resource exhaustion attacks. Patches are available in versions 4.10.10 (for 4.x branch) and 5.2.1 (for 5.x branch), which implement improved URL validation and additional checks before downloading resources.

Affected products

  • Parse Community Parse Server <4.10.10 and >=5.0.0 <5.2.1

Timeline

  • 2022-05-01: disclosed
  • 2022-05-04: advisory
  • 2022-05-04: patched: versions 4.10.10 and 5.2.1 released

References