Executive brief
Parse Server is an open-source backend platform used to power mobile and web applications with database services. When configured with PostgreSQL, a flaw in how the server processes regular expression queries allows unauthenticated attackers to inject malicious SQL commands, potentially exposing or modifying sensitive application data without authorization.
Technical details
The vulnerability is a SQL injection flaw (CWE-89) in the literalizeRegexPart function of Parse Server when PostgreSQL is the configured database backend. The vulnerability exists in the regex pattern processing logic that fails to properly sanitize user input before constructing SQL queries. An unauthenticated attacker on the network can exploit this by sending specially crafted query requests without requiring valid credentials or user interaction. Successful exploitation allows the attacker to read, modify, or delete database records. The vulnerability was patched in Parse Server versions 6.5.0 and later (including 7.0.0-alpha.20 and subsequent releases).
Affected products
- Parse Community Parse Server <6.5.0
Timeline
- 2024-03-01: disclosed
- 2024-03-01: patched: Parse Server 6.5.0 and 7.0.0-alpha.20 and later