Vulnerabilities > CVE-2024-47183 - Incorrect Authorization vulnerability in Parseplatform Parse Server

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
parseplatform
CWE-863

Summary

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.

Vulnerable Configurations

Part Description Count
Application
Parseplatform
1

Common Weakness Enumeration (CWE)