Executive brief
Parse Server is a backend framework for building mobile and web applications. An attacker can exploit a prototype pollution vulnerability in the MongoDB BSON parser to achieve remote code execution on servers running affected versions. This allows complete compromise of the application, including unauthorized access to all stored data and the ability to modify or delete information.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) in the MongoDB database adapter of Parse Server. An attacker can send specially crafted data that pollutes the JavaScript object prototype through the BSON parser, subsequently triggering remote code execution. The attack requires network access to the Parse Server instance and does not require authentication or user interaction. The vulnerability affects all versions prior to 5.5.2 and versions 6.0.0 through 6.2.0. Patches are available in versions 5.5.2 and 6.2.1 and later. As a workaround, administrators can disable remote code execution through the MongoDB BSON parser.
Affected products
- parse-community parse-server <5.5.2, >=6.0.0 <6.2.1
Timeline
- 2023-06-28: disclosed: Advisory published
- 2023-06-28: patched: Patches released in versions 5.5.2 and 6.2.1
References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-462x-c3jw-7vr6
- https://github.com/parse-community/parse-server/issues/8674
- https://github.com/parse-community/parse-server/issues/8675
- https://github.com/parse-community/parse-server/commit/3dd99dd80e27e5e1d99b42844180546d90c7aa90
- https://github.com/parse-community/parse-server/commit/5fad2928fb8ee17304abcdcf259932f827d8c81f
- https://github.com/parse-community/parse-server