GHSA-qf8x-vqjv-92gr
Dashboard / Vulnerabilities / GHSA-qf8x-vqjv-92gr
Summary: Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
Details: ### Impact Weak validation of the Apple certificate URL in the Apple Game Center authentication adapter allows to bypass authentication and makes the server vulnerable to DoS attacks. ### Patches The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
References: https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr, https://nvd.nist.gov/vuln/detail/CVE-2022-24901, https://github.com/parse-community/parse-server/commit/af4a0417a9f3c1e99b3793806b4b18e04d9fa999, https://github.com/parse-community/parse-server
Affected packages
Package
Name: parse-server
Purl: pkg:npm/parse-server
Affected ranges
Type: SEMVER
Events:
