parse-server@8.0.2-alpha.1 vulnerabilities

An express module providing a Parse-compatible API server

  • latest version

    8.1.0

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    18 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the parse-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Authentication

    parse-server is a version of the Parse backend that can be deployed to any infrastructure that can run Node.js.

    Affected versions of this package are vulnerable to Improper Authentication due to the improper handling of authentication credentials across multiple applications. An attacker can exploit this vulnerability to authenticate using credentials from one application in another unrelated application by leveraging shared authentication providers.

    How to fix Improper Authentication?

    Upgrade parse-server to version 7.5.2, 8.0.2 or higher.

    <7.5.2>=8.0.0 <8.0.2