Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Parse Server: Session update endpoint allows overwriting server-generated session fields
Vulnerability Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and createdWith when updating their own session via the REST API. This allows bypassing the server's configured session lifetime policy, making a session effectively permanent. This issue has been patched in versions 8.6.57 and 9.6.0-alpha.48.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Parse Server 安全漏洞
Vulnerability Description
Parse Server是Parse Platform开源的一个开源后端,可以部署到任何可以运行 Node.js 的基础设施。 Parse Server 8.6.57之前版本和9.6.0-alpha.48之前版本存在安全漏洞,该漏洞源于经过身份验证的用户可通过REST API更新自己的会话时覆盖服务器生成的会话字段,可能导致绕过会话生存期策略。
CVSS Information
N/A
Vulnerability Type
N/A