GHSA-xw6g-jjvf-wwf9
Dashboard / Vulnerabilities / GHSA-xw6g-jjvf-wwf9
Summary: Invalid file request can crash server
Details: ### Impact Certain types of invalid files requests are not handled properly and can crash the server. If you are running multiple Parse Server instances in a cluster, the availability impact may be low; if you are running Parse Server as a single instance without redundancy, the availability impact may be high. ### Patches To prevent this, invalid requests are now properly handled. ### Workarounds None ### References - https://github.com/parse-community/parse-server/security/advisories/GHSA-xw6g-jjvf-wwf9 - https://github.com/parse-community/parse-server ### For more information - For questions or comments about this vulnerability visit our [community forum](http://community.parseplatform.org/) or [community chat](http://chat.parseplatform.org/) - Report other vulnerabilities at [report.parseplatform.org](https://report.parseplatform.org/)
References: https://github.com/parse-community/parse-server/security/advisories/GHSA-xw6g-jjvf-wwf9, https://nvd.nist.gov/vuln/detail/CVE-2022-31089, https://github.com/parse-community/parse-server/commit/5be375dec2fa35425c1003ae81c55995ac72af92, https://github.com/parse-community/parse-server
Affected packages
Package
Name: parse-server
Purl: pkg:npm/parse-server
Affected ranges
Type: SEMVER
Events:
