NA

CVE-2022-39313

Published: 24/10/2022 Updated: 14/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions before 4.10.17, and before 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

parseplatform parse-server