CVE-2022-36079
Last modified
CVE-2022-36079 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Parse Server, prefixed by `_`) and protected fields (user defined) can be used as query constraints. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Parse Server, prefixed by `_`) and protected fields (user defined) can be used as query constraints. Internal and protected fields are removed by Parse Server and are only returned to the client using a valid master key. However, using query constraints, these fields can be guessed by enumerating until Parse Server, prior to versions 4.10.14 or 5.2.5, returns a response object. The patch available in versions 4.10.14 and 5.2.5 requires the maser key to use internal and protected fields as query constraints. As a workaround, implement a Parse Cloud Trigger `beforeFind` and manually remove the query constraints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Parseplatform | Parse-Server | < 4.10.14 |
| Parseplatform | Parse-Server | >= 5.0.0, < 5.2.5 |
References
- https://github.com/parse-community/parse-server/commit/634c44acd18f6ee6ec60fac89a2b602d92799becPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/e39d51bd329cd978589983bd659db46e1d45aad4Patch, Third Party Advisory
- https://github.com/parse-community/parse-server/issues/8143Issue Tracking, Third Party Advisory
- https://github.com/parse-community/parse-server/issues/8144Issue Tracking, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/4.10.14Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/5.2.5Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/634c44acd18f6ee6ec60fac89a2b602d92799becPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/e39d51bd329cd978589983bd659db46e1d45aad4Patch, Third Party Advisory
- https://github.com/parse-community/parse-server/issues/8143Issue Tracking, Third Party Advisory
- https://github.com/parse-community/parse-server/issues/8144Issue Tracking, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/4.10.14Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/5.2.5Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36079?
How severe is CVE-2022-36079?
How do I fix CVE-2022-36079?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36073RubyGems.org is the Ruby community gem host. A bug in passwo…8.8
- CVE-2022-36074Nextcloud server is an open source personal cloud product. A…7.5
- CVE-2022-36075Nextcloud files access control is a nextcloud app to manage …4.3
- CVE-2022-36076NodeBB Forum Software is powered by Node.js and supports eit…7.5
- CVE-2022-36077The Electron framework enables writing cross-platform deskto…6.1
- CVE-2022-36078Binary provides encoding/decoding in Borsh and other formats…7.5
- CVE-2022-3608Cross-site Scripting (XSS) - Stored in GitHub repository tho…8.4
- CVE-2022-36080Wikmd is a file based wiki that uses markdown. Prior to vers…6.1
- CVE-2022-36081Wikmd is a file based wiki that uses markdown. Prior to vers…7.5
- CVE-2022-36082mangadex-downloader is a command-line tool to download manga…5.3
- CVE-2022-36083JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, J…5.3
- CVE-2022-36084cruddl is software for creating a GraphQL API for a database…8.8
Are you affected by CVE-2022-36079?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
