CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way. | 7.7 |
High |
||
parse-server before 3.6.0 allows account enumeration. | 5.3 |
Medium |
||
parse-server before 3.4.1 allows DoS after any POST to a volatile class. | 7.5 |
High |