SB2023062920 - Prototype pollution in Parse Server



SB2023062920 - Prototype pollution in Parse Server

Published: June 29, 2023 Updated: August 25, 2023

Security Bulletin ID SB2023062920
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Prototype pollution (CVE-ID: CVE-2023-36475)

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation within the MongoDB BSON parser. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation or lead to code execution.


Remediation

Install update from vendor's website.