parse-server is vulnerable to Generation of Error Message Containing Sensitive Information
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure via Detailed Error Messages, where Parse Server returns excessive information in error responses, revealing internal authentication logic and system details. An attacker can exploit this by analyzing these detailed error messages to infer security mechanisms, potentially facilitating targeted attacks like probing for access key requirements or other access control weaknesses.
You are affected if you are using a version that falls within the vulnerable range.
parse-server is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.2.8 - 8.4.0.
Upgrade the parse-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant