Junglewise Threat Intelligence

CVE-2024-27298: Parse Server literalizeRegexPart SQL injection

CVE-2024-27298 · Severity: low · CVSS 3.1 · Published 2024-03-01

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is an open-source backend platform used to power mobile and web applications with database services. When configured with PostgreSQL, a flaw in how the server processes regular expression queries allows unauthenticated attackers to inject malicious SQL commands, potentially exposing or modifying sensitive application data without authorization.

Technical details

The vulnerability is a SQL injection flaw (CWE-89) in the literalizeRegexPart function of Parse Server when PostgreSQL is the configured database backend. The vulnerability exists in the regex pattern processing logic that fails to properly sanitize user input before constructing SQL queries. An unauthenticated attacker on the network can exploit this by sending specially crafted query requests without requiring valid credentials or user interaction. Successful exploitation allows the attacker to read, modify, or delete database records. The vulnerability was patched in Parse Server versions 6.5.0 and later (including 7.0.0-alpha.20 and subsequent releases).

Affected products

  • Parse Community Parse Server <6.5.0

Timeline

  • 2024-03-01: disclosed
  • 2024-03-01: patched: Parse Server 6.5.0 and 7.0.0-alpha.20 and later

References