CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way. | 7.7 |
Haute |
||
parse-server before 3.6.0 allows account enumeration. | 5.3 |
Moyen |
||
parse-server before 3.4.1 allows DoS after any POST to a volatile class. | 7.5 |
Haute |