Parse Server 版本 <= 8.6.87 和 >= 9.0.0 < 9.10.1-alpha.7 内置的 LDAP 身份验证适配器中存在一个身份验证绕过漏洞。该适配器将客户端提供的密码直接转发给目录服务,而没有验证密码是否已提供,并将来自目录服务的任何非错误响应都视为身份验证成功的证明。零长度的凭证会将 LDAP 简单绑定(simple bind)转变为 RFC 4513 第 5.1.2 节中描述的匿名身份验证机制,而某些目录服务(包括默认配置的 Active Directory)会对此返回成功响应,并将
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| parse-community | parse-server | 9.0.0< 9.10.1-alpha.7 |
affected |
9.10.1-alpha.7 |
unaffected | ||
< 8.6.88 |
affected | ||
8.6.88 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| parse-community | parse-server | 9.0.0 ~ 9.10.1-alpha.7 | - |
|
| parse-community | parse-server | 0 ~ 8.6.88 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet