Invalid file request can crash server
High severity
GitHub Reviewed
Published
Jun 17, 2022
in
parse-community/parse-server
•
Updated Jan 27, 2023
Package
Affected versions
< 4.10.12
>= 5.0.0, < 5.2.3
Patched versions
4.10.12
5.2.3
Description
Published to the GitHub Advisory Database
Jun 20, 2022
Reviewed
Jun 20, 2022
Published by the National Vulnerability Database
Jun 27, 2022
Last updated
Jan 27, 2023
Impact
Certain types of invalid files requests are not handled properly and can crash the server. If you are running multiple Parse Server instances in a cluster, the availability impact may be low; if you are running Parse Server as a single instance without redundancy, the availability impact may be high.
Patches
To prevent this, invalid requests are now properly handled.
Workarounds
None
References
For more information
References