parse-server is vulnerable to Weak Password Recovery Mechanism
48
Medium Risk
Versions of this package impacted by this issue have a weak password recovery mechanism due to the inclusion of the username in password reset and email verification links. This exposes personally identifiable information in logs and allows full account compromise if the link is shared. Since the link already contains a perishable token, the username is unnecessary and should be removed to prevent attackers from identifying the affected account.
You are affected if you are using a version which is within vulnerability ranges.
parse-server is vulnerable to Weak Password Recovery Mechanism in versions 1.0.0 - 7.4.0.
Upgrade the parse-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant