Skip to content

Potentially critical bug when making POST request against /parse/classes/_Audience

Low
acinader published GHSA-2479-qvv7-47qq Jun 12, 2019 · 1 comment

Package

npm parse-server (npm)

Affected versions

< 3.4.1

Patched versions

3.4.1

Description

Impact

If a POST request is made to /parse/classes/_Audience (or other volatile class), any subsuquent POST requests result in an internal server error (500).

Patches

Afflicted installations will also have to remove the offending collection from their database.

Yes, patched in 3.4.1

Workarounds

Yes, user can apply: 8709daf

References

Nothing other than this advisory at this time

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs