Junglewise Threat Intelligence

CVE-2022-31083: Parse Server authentication bypass in Apple Game Center adapter

CVE-2022-31083 · Severity: low · CVSS 3.1 · Published 2022-06-17

Technologies: Parse Server.

Executive brief

Parse Server is a backend-as-a-service platform that handles application authentication and data management. The Apple Game Center authentication adapter fails to validate certificates, allowing an attacker to bypass authentication by presenting a fake certificate from a trusted Apple domain. This could enable unauthorized access to applications using this authentication method.

Technical details

The vulnerability is a certificate validation bypass (CWE-295) in the Apple Game Center authentication adapter within Parse Server. The adapter fails to validate the certificate presented by the server, allowing an attacker to provide a crafted certificate via a URL in the authData object to bypass authentication checks. The attack requires network access to make the fake certificate accessible via certain Apple domains but does not require authentication or user interaction. An attacker can achieve complete authentication bypass, potentially gaining unauthorized access to applications relying on this authentication method. The vulnerability was patched by introducing a rootCertificateUrl property that validates certificates against a specified root certificate URL.

Affected products

  • Parse Server before 4.10.11 and 5.0.0 through before 5.2.2

Timeline

  • 2022-06-17: disclosed
  • 2022-06-17: patched: Fixed in versions 4.10.11 and 5.2.2

References