{"id":"BIT-parse-2024-47183","summary":"Parse Server's custom object ID allows to acquire role privileges","details":"Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0.","aliases":["CVE-2024-47183","GHSA-8xq9-g7ch-35hg"],"modified":"2026-09-08T08:48:24.477491028Z","published":"2024-10-08T07:14:06.158Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:*"]},"references":[{"type":"FIX","url":"https://github.com/parse-community/parse-server/commit/13ee52f0d19ef3a3524b3d79aea100e587eb3cfc"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/commit/1bfbccf9ee7ea77533b2b2aa7c4c69f3bd35e66f"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/9317"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/pull/9318"},{"type":"ADVISORY","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47183"}],"affected":[{"package":{"name":"parse","ecosystem":"Bitnami","purl":"pkg:bitnami/parse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.3.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/parse/BIT-parse-2024-47183.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}],"schema_version":"1.9.0"}