parse-server@8.2.2-alpha.1 vulnerabilities

An express module providing a Parse-compatible API server

  • latest version

    8.2.3

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    12 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the parse-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    parse-server is a version of the Parse backend that can be deployed to any infrastructure that can run Node.js.

    Affected versions of this package are vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere via the Parse Server GraphQL API process. An attacker can obtain sensitive schema metadata by sending unauthenticated requests to the API endpoint.

    How to fix Exposure of Sensitive System Information to an Unauthorized Control Sphere?

    Upgrade parse-server to version 7.5.3, 8.2.2 or higher.

    >=5.3.0 <7.5.3>=8.0.0 <8.2.2