VulnerabilityModified
CVE-2020-15126
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.
MEDIUM 6.5EPSS 1.07%
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- parseplatform/parse server
- Source
- security-advisories@github.com
References
- https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aaPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73Third Party Advisory
- https://github.com/parse-community/parse-server/blob/master/CHANGELOG.md#430Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aaPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/security/advisories/GHSA-236h-rqv8-8q73Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.