parse-server vulnerabilities

An express module providing a Parse-compatible API server

  • latest version

    8.2.4

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the parse-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    >=5.3.0 <7.5.3>=8.0.0 <8.2.2
    • M
    Improper Authentication

    <7.5.2>=8.0.0 <8.0.2
    • H
    Improper Authorization

    <6.5.9>=7.0.0 <7.3.0
    • H
    SQL Injection

    <6.5.7>=7.0.0 <7.1.0
    • C
    Improper Input Validation

    <6.5.5>=7.0.0-alpha.1 <7.0.0-alpha.29
    • C
    SQL Injection

    <6.5.0>=7.0.0-alpha.1 <7.0.0-alpha.20
    • H
    Uncontrolled Resource Consumption ('Resource Exhaustion')

    >=1.0.0 <5.5.6>=6.0.0 <6.3.1
    • H
    Access Restriction Bypass

    >=1.0.0 <5.5.5>=6.0.0 <6.2.2
    • C
    Prototype Pollution

    <5.5.2>=6.0.0-alpha.1 <6.2.1
    • M
    Arbitrary File Upload

    <5.5.0>=6.0.0 <6.2.0
    • H
    Authentication Bypass

    <5.4.1
    • H
    Prototype Pollution

    <4.10.20>=5.0.0 <5.3.3
    • H
    Prototype Pollution

    <4.10.19>=5.0.0 <5.3.2
    • C
    Prototype Pollution

    <4.10.18>=5.0.0 <5.3.1
    • H
    Denial of Service (DoS)

    <4.10.17>=5.0.0 <5.2.8
    • M
    Authentication Bypass

    <4.10.15>=5.0.0 <5.2.6
    • L
    Improper Authentication

    <4.10.16>=5.0.0 <5.2.7
    • M
    Information Exposure

    <4.10.14>=5.0.0 <5.2.5
    • H
    Information Exposure

    <4.10.13>=5.0.0 <5.2.4
    • H
    Denial of Service (DoS)

    <4.10.12>=5.0.0 <5.2.3
    • C
    Authentication Bypass

    <4.10.11>=5.0.0 <5.2.2
    • H
    Authentication Bypass

    <4.10.10>=5.0.0 <5.2.1
    • C
    Prototype Pollution

    <4.10.7
    • H
    Improper Authentication

    <4.10.4
    • H
    Unsafe Dependency Resolution

    >=4.6.0 <4.10.0>=4.0.3 <4.1.0>=4.0.0-beta1 <4.0.2
    • H
    Denial of Service (DoS)

    <4.10.3
    • M
    Information Exposure

    <4.5.1
    • M
    Insecure Storage of Sensitive Information

    >=3.10.0 <4.5.0
    • M
    Operation on a Resource after Expiration or Release

    <4.4.0
    • M
    Access Restriction Bypass

    >=3.5.0 <4.3.0
    • H
    Improper Input Validation

    <4.1.0
    • M
    Account Enumeration

    <3.6.0
    • H
    Denial of Service (DoS)

    <3.4.1

    Package versions

    465 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    8.2.41 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.4-alpha.12 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.31 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.3-alpha.113 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.210 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    8.2.2-alpha.110 Jul, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    8.2.11 Jun, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    8.2.1-alpha.214 May, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    8.2.1-alpha.13 May, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    8.2.01 May, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L