
Cloud Vulnerability DB
A community-led vulnerabilities database
Parse Server, an open source backend that can be deployed to any Node.js infrastructure, was found to contain a prototype pollution vulnerability (CVE-2022-41878) in versions prior to 5.3.2 or 4.10.19. The vulnerability was discovered and reported through the Zero Day Initiative program (ZDI Advisory, GitHub Advisory).
The vulnerability exists within the buildUpdatedObject function of Parse Server. The specific flaw results from the lack of control over modifications to attributes of object prototypes. Keywords specified in the Parse Server option requestKeywordDenylist can be injected via Cloud Code Webhooks or Triggers, resulting in the keyword being saved to the database and bypassing the requestKeywordDenylist option. The vulnerability has been assigned a CVSS score of 7.2 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (ZDI Advisory).
An attacker who successfully exploits this vulnerability can leverage it to execute code in the context of the service account. The vulnerability affects the confidentiality, integrity, and availability of the system, with all three aspects rated as High in the CVSS scoring (GitHub Advisory).
The vulnerability requires authentication to exploit, and while it has a network attack vector, it requires high privileges. The attack complexity is rated as Low, indicating that the attack can be performed with relative ease once the necessary privileges are obtained (ZDI Advisory).
Parse has issued updates to correct this vulnerability in versions 4.10.19 and 5.3.2. As a workaround, users can configure their firewall to only allow trusted servers to make requests to the Parse Server Cloud Code Webhooks API, or block the API completely if not using the feature (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."