GHSA-r657-33vp-gp22

    Dashboard / Vulnerabilities / GHSA-r657-33vp-gp22

    GHSA-r657-33vp-gp22

    Published: 21 Sept 2022Last Modified: 6 Dec 2023

    Summary: parse-server auth adapter app ID validation can be circumvented

    Details: ### Impact Validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented. This fixes a vulnerability that affects configurations which allow users to authenticate using the Parse Server authentication adapter for _Facebook_ or _Spotify_ and where the server-side authentication adapter configuration `appIds` is set as a string (e.g. `abc`) instead of an array of strings (e.g. `["abc"]`). The vulnerability makes it possible to authenticate requests which are coming from a _Facebook_ or _Spotify_ app with a different app ID than the one specified in the `appIds` configuration. Both adapters still validate the access token with the respective authentication provider. An app ID is automatically assigned by the authentication provider. For this vulnerability to be exploited, an attacker would have to be assigned an app ID by the authentication provider which is a sub-set of the server-side configured app ID. The documentation did not explicitly specify that the parameter `appIds` must be set as an array of strings and setting a string also worked. Therefore, there is a possibility that there are deployments where `appIds` is set as a string, making them vulnerable. ### Patches The fix makes Parse Server check the type of the value set for `appIds` and throws an error if the value is not an array. ### Workarounds No known workarounds. ### References - GitHub advisory [GHSA-r657-33vp-gp22](https://github.com/parse-community/parse-server/security/advisories/GHSA-r657-33vp-gp22)

    Affected packages

    Package

    Name: parse-server

    Purl: pkg:npm/parse-server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -4.10.16

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r657-33vp-gp22 | CVE-DB