Junglewise Threat Intelligence

CVE-2023-22474: Parse Server IP spoofing in masterKeyIps validation

CVE-2023-22474 · Severity: low · CVSS 3.1 · Published 2023-01-31

Technologies: parse-server (npm), Parse Community Parse Server. Vendors: npm, Parse Community.

Executive brief

Parse Server is a backend framework that manages authentication and data access control. When not deployed behind a proxy, attackers can forge the x-forwarded-for HTTP header to impersonate whitelisted IP addresses, bypassing the masterKeyIps security feature that restricts master key access to trusted networks. This allows unauthorized access to sensitive operations that should be restricted to administrators.

Technical details

Parse Server trusts the x-forwarded-for HTTP header to determine client IP addresses without validating whether a proxy is actually in place. The masterKeyIps option relies on this IP detection to restrict master key operations to whitelisted IPs (CWE-290: Improper Input Validation). An unauthenticated network attacker can set an arbitrary x-forwarded-for header value to match a whitelisted IP, bypassing IP-based access controls. This requires high privileges (administrative masterKey) to exploit the bypass itself, but the impact is confidentiality and integrity violations through unauthorized master key access. The fix (version 5.4.1+) requires explicit configuration of the trustProxy option to validate whether the application runs behind a reverse proxy.

Affected products

  • Parse Community Parse Server < 5.4.1

Timeline

  • 2023-01-31: disclosed
  • 2023-01-31: patched: Version 5.4.1 released with fix

References

Related threats