{"id":"GHSA-xprv-wvh7-qqqx","summary":"Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers","details":"### Impact\n\nKeywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers. This will result in the keyword being saved to the database, bypassing the `requestKeywordDenylist` option.\n\n### Patches\n\nImproved keyword detection.\n\n### Workarounds\n\nConfigure your firewall to only allow trusted servers to make request to the Parse Server Cloud Code Webhooks API, or block the API completely if you are not using the feature.\n\n### Collaborators\n\nMikhail Shcherbakov, Cristian-Alexandru Staicu and Musard Balliu working with Trend Micro Zero Day Initiative\n\n### References\n- https://github.com/parse-community/parse-server/security/advisories/GHSA-xprv-wvh7-qqqx\n","aliases":["BIT-parse-2022-41878","CVE-2022-41878"],"modified":"2023-12-06T01:02:37.826625Z","published":"2022-11-09T20:47:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-11-09T20:47:27Z","nvd_published_at":"2022-11-10T23:15:00Z","cwe_ids":["CWE-1321"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-xprv-wvh7-qqqx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41878"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/8301"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/8302"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/0a2d412e265992d53a670011afd9d2578562adc3"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/6728da1e3591db1e27031d335d64d8f25546a06f"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"affected":[{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.10.19"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-xprv-wvh7-qqqx/GHSA-xprv-wvh7-qqqx.json"}},{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-xprv-wvh7-qqqx/GHSA-xprv-wvh7-qqqx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}