parse-server is vulnerable to Generation of Error Message Containing Sensitive Information
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure via Detailed Error Messages, where Parse Server returns excessive information in error responses, revealing internal authentication logic and system details. An attacker can exploit this by analyzing these detailed error messages to infer security mechanisms, potentially facilitating targeted attacks like probing for access key requirements or other access control weaknesses.
You are affected if you are using a version that falls within the vulnerable range.
parse-server is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.2.8 - 8.4.0.
Upgrade the parse-server library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant