Parse Server crashes with query parameter
High severity
GitHub Reviewed
Published
Sep 2, 2021
in
parse-community/parse-server
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Sep 2, 2021
Reviewed
Sep 2, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Jan 30, 2023
Impact
Parse Server crashes when if a query request contains an invalid value for the
explain
option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch.Patches
Upgrade to Parse Server 4.10.3
References