ZeroHour

CVE-2020-15270

CVSS 3.1
4.3 medium
EPSS
1%p65
Published
()
Modified
Description

Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.

Vendors
parseplatform
Products
parse-server
Weakness
CWE-672
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.