CVE-2022-39231
Last modified
CVE-2022-39231 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented. Configurations which allow users to authenticate using the Parse Server authentication adapter where `appIds` is set as a string instead of an array of strings authenticate requests from an app with a different app ID than the one specified in the `appIds` configuration. For this vulnerability to be exploited, an attacker needs to be assigned an app ID by the authentication provider which is a sub-set of the server-side configured app ID. This issue is patched in versions 4.10.16 and 5.2.7. There are no known workarounds.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Parseplatform | Parse-Server | < 4.10.16 |
| Parseplatform | Parse-Server | >= 5.0.0, < 5.2.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39231?
How severe is CVE-2022-39231?
How do I fix CVE-2022-39231?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-39226Discourse is an open source discussion platform. In versions…4.3
- CVE-2022-39227python-jwt is a module for generating and verifying JSON Web…9.1
- CVE-2022-39228vantage6 is a privacy preserving federated learning infrastr…6.5
- CVE-2022-39229Grafana is an open source data visualization platform for me…4.3
- CVE-2022-3923The ActiveCampaign for WooCommerce WordPress plugin before 1…4.3
- CVE-2022-39230fhir-works-on-aws-authz-smart is an implementation of the au…6.5
- CVE-2022-39232Discourse is an open source discussion platform. Starting wi…4.3
- CVE-2022-39233Tuleap is a Free & Open Source Suite to improve management o…5.4
- CVE-2022-39234GLPI stands for Gestionnaire Libre de Parc Informatique. GLP…8.8
- CVE-2022-39236Matrix Javascript SDK is the Matrix Client-Server SDK for Ja…5.3
- CVE-2022-39237syslabs/sif is the Singularity Image Format (SIF) reference …9.8
- CVE-2022-39238Arvados is an open source platform for managing and analyzin…8.8
Are you affected by CVE-2022-39231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
