Intel

AIKIDO-2025-10887

parse-server is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

JSparse-server
2.2.8 - 8.4.0
Fixed in 8.5.0

TL;DR

Affected versions of this package are vulnerable to Information Disclosure via Detailed Error Messages, where Parse Server returns excessive information in error responses, revealing internal authentication logic and system details. An attacker can exploit this by analyzing these detailed error messages to infer security mechanisms, potentially facilitating targeted attacks like probing for access key requirements or other access control weaknesses.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

parse-server is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.2.8 - 8.4.0.

How to fix this

Upgrade the parse-server library to the patch version.