CVE-2024-27298
01.03.2024, 18:15
parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.
| Vendor | Product | Version |
|---|---|---|
| parseplatform | parse-server | 𝑥 < 6.5.0 |
| parseplatform | parse-server | 6.5.0:alpha1 |
| parseplatform | parse-server | 6.5.0:alpha2 |
| parseplatform | parse-server | 6.5.0:beta1 |
| parseplatform | parse-server | 7.0.0:alpha1 |
| parseplatform | parse-server | 7.0.0:alpha10 |
| parseplatform | parse-server | 7.0.0:alpha11 |
| parseplatform | parse-server | 7.0.0:alpha12 |
| parseplatform | parse-server | 7.0.0:alpha13 |
| parseplatform | parse-server | 7.0.0:alpha14 |
| parseplatform | parse-server | 7.0.0:alpha15 |
| parseplatform | parse-server | 7.0.0:alpha16 |
| parseplatform | parse-server | 7.0.0:alpha17 |
| parseplatform | parse-server | 7.0.0:alpha18 |
| parseplatform | parse-server | 7.0.0:alpha19 |
| parseplatform | parse-server | 7.0.0:alpha2 |
| parseplatform | parse-server | 7.0.0:alpha3 |
| parseplatform | parse-server | 7.0.0:alpha4 |
| parseplatform | parse-server | 7.0.0:alpha5 |
| parseplatform | parse-server | 7.0.0:alpha6 |
| parseplatform | parse-server | 7.0.0:alpha7 |
| parseplatform | parse-server | 7.0.0:alpha8 |
| parseplatform | parse-server | 7.0.0:alpha9 |
𝑥
= Vulnerable software versions
References