Intel

AIKIDO-2024-10157

parse-server is vulnerable to SQL injection

SQL injectionCVE-2024-39309 Published Jul 1, 2024

98

Critical Risk

This Affects:

jsparse-server
2.2.14 - 6.5.6
Fixed in 6.5.7
7.0.0 - 7.0.0
Fixed in 7.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to SQL injection.

Who does this affect?

You are affected if you use a vulnerable version of the package and configure parse-server to use the PostgreSQL database.

Background info

parse-server is vulnerable to SQL injection in versions 2.2.14 - 6.5.6 and 7.0.0 - 7.0.0.

How to fix this

Upgrade parse-server to a patch version.