CVE Feed

    Dashboard / CVE / CVE-2022-24760

    CVE-2022-24760

    Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any other database backend as well. This vulnerability has been confirmed on Linux (Ubuntu) and Windows. Users are advised to upgrade as soon as possible. The only known workaround is to manually patch your installation with code referenced at the source GHSA-p6h4-93qp-jhcm.

    Published:Mar 11, 2022
    Last Modified:Apr 22, 2025
    EPS:Mar 11, 2022
    EPSS Score:0.5828
    CVSS Score:10

    Affected Products

    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Parseplatform
    Product
    Parse-server

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High