parse-server crashes when receiving file download request with invalid byte range
High severity
GitHub Reviewed
Published
Oct 15, 2022
in
parse-community/parse-server
•
Updated Sep 18, 2023
Package
Affected versions
< 4.10.17
>= 5.0.0, < 5.2.8
Patched versions
4.10.17
5.2.8
Description
Published to the GitHub Advisory Database
Oct 18, 2022
Reviewed
Oct 18, 2022
Published by the National Vulnerability Database
Oct 24, 2022
Last updated
Sep 18, 2023
Impact
Parse Server crashes when a file download request is received with an invalid byte range.
Patches
Improved parsing of the range parameter to properly handle invalid range requests.
Workarounds
None
References
References