High severity8.2NVD Advisory· Published Jun 30, 2022· Updated Jun 17, 2026
CVE-2022-31112
CVE-2022-31112
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now removes protected fields from the client response. Users are advised to upgrade. Users unable t upgrade should use Parse.Cloud.afterLiveQueryEvent to manually remove protected fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
parse-servernpm | < 4.10.13 | 4.10.13 |
parse-servernpm | >= 5.0.0, < 5.2.4 | 5.2.4 |
Affected products
4- osv-coords2 versions
< 4.10.13+ 1 more
- (no CPE)range: < 4.10.13
- (no CPE)range: < 4.10.13
- Range: < 4.10.13
Patches
Vulnerability mechanics
References
9- github.com/parse-community/parse-server/commit/309f64ced8700321df056fb3cc97f15007a00df1nvdPatchThird Party AdvisoryWEB
- github.com/parse-community/parse-server/commit/9fd4516cde5c742f9f29dd05468b4a43a85639a6nvdPatchThird Party AdvisoryWEB
- github.com/parse-community/parse-server/issues/8073nvdIssue TrackingPatchRelease NotesThird Party AdvisoryWEB
- github.com/parse-community/parse-server/pull/8074nvdPatchRelease NotesThird Party AdvisoryWEB
- github.com/advisories/GHSA-crrq-vr9j-fxxhghsaADVISORY
- github.com/parse-community/parse-server/releases/tag/5.2.4nvdRelease NotesThird Party AdvisoryWEB
- github.com/parse-community/parse-server/security/advisories/GHSA-crrq-vr9j-fxxhnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-31112ghsaADVISORY
- github.com/parse-community/parse-server/commit/054f3e6ab01d66a0dcfb77725af28eac1485b375ghsaWEB
News mentions
0No linked articles in our index yet.