VulnerabilityModified
CVE-2020-26288
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
MEDIUM 6.5EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- parseplatform/parse-server
- Source
- security-advisories@github.com
References
- https://github.com/parse-community/parse-server/commit/da905a357d062ab4fea727a21eac231acc2ed92aPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/4.5.0Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/security/advisories/GHSA-4w46-w44m-3jq3Third Party Advisory
- https://www.npmjs.com/package/parse-serverProduct, Third Party Advisory
- https://github.com/parse-community/parse-server/commit/da905a357d062ab4fea727a21eac231acc2ed92aPatch, Third Party Advisory
- https://github.com/parse-community/parse-server/releases/tag/4.5.0Release Notes, Third Party Advisory
- https://github.com/parse-community/parse-server/security/advisories/GHSA-4w46-w44m-3jq3Third Party Advisory
- https://www.npmjs.com/package/parse-serverProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.