Skip to content

Server crashes with invalid explain query parameter

High
mtrezza published GHSA-xqp8-w826-hh6x Sep 2, 2021

Package

npm parse-server (npm)

Affected versions

< 4.10.3

Patched versions

4.10.3

Description

Impact

Parse Server crashes when if a query request contains an invalid value for the explain option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch.

Patches

Upgrade to Parse Server 4.10.3.

Workarounds

No known workaround.

References

https://jira.mongodb.org/browse/NODE-3463

Severity

High

CVE ID

CVE-2021-39187

Weaknesses

No CWEs

Credits