ZeroHour

CVE-2020-15126

CVSS 3.1
6.5 medium
EPSS
1%p63
Published
()
Modified
Description

In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.

Vendors
parseplatform
Products
parse server
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.