VYPR

Bitnami package

parse

pkg:bitnami/parse

Vulnerabilities (120)

  • CVE-2026-30848LowMar 7, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outsi

  • CVE-2026-30835MedMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.7 and 9.5.0-alpha.6, malformed $regex query parameter (e.g. [abc) causes the database to return a structured error object that is passed unsanitized thro

  • CVE-2026-30229HigMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impe

  • CVE-2026-30228MedMar 6, 2026
    affected < 9.5.0fixed 9.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This

  • CVE-2026-29182HigMar 6, 2026
    affected < 9.4.1fixed 9.4.1

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's readOnlyMasterKey option allows access with master-level read privileges but is documented to deny all write operation

  • CVE-2026-27804CriFeb 26, 2026
    affected < 8.6.3fixed 8.6.3

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google accou

  • CVE-2025-68150MedDec 16, 2025
    affected < 8.6.2fixed 8.6.2

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enable

  • CVE-2025-68115MedDec 16, 2025
    affected < 8.6.1fixed 8.6.1

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. Th

  • CVE-2025-67727CriDec 12, 2025
    affected < 8.6.0fixed 8.6.0

    Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and

  • CVE-2025-64502MedNov 10, 2025
    affected < 8.5.0fixed 8.5.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information about query execution plans, including index usage, collection scanning behavior, and performance metrics. Prior to

  • CVE-2025-64430HigNov 7, 2025
    affected >= 4.2.0, < 7.5.4fixed 7.5.4

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to up

  • CVE-2025-53364MedJul 10, 2025
    affected >= 5.3.0, < 8.2.2fixed 8.2.2

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the maste

  • CVE-2025-30168MedMar 21, 2025
    affected < 8.0.2fixed 8.0.2

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication credentials of some specific authentication providers to be used acros

  • CVE-2024-47183HigOct 4, 2024
    affected < 7.3.0fixed 7.3.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vul

  • CVE-2024-39309CriJul 1, 2024
    affected < 7.2.0fixed 7.2.0

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection

  • CVE-2024-29027CriMar 19, 2024
    affected < 6.5.5fixed 6.5.5

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud Job name crashes the server and may allow for code injection, internal

  • CVE-2024-27298CriMar 1, 2024
    affected < 6.5.0fixed 6.5.0

    parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.

  • CVE-2023-46119HigOct 25, 2023
    affected >= 1.0.0, < 5.5.6fixed 5.5.6

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.

  • CVE-2023-41058HigSep 4, 2023
    affected < 5.5.5fixed 5.5.5

    Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Parse.Query`. This can pose a vulnerability for deployments where the `beforeFind` trigger is used as a security layer to modify the i

  • CVE-2023-36475CriJun 28, 2023
    affected < 5.5.2fixed 5.5.2

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in ve

Page 5 of 6