PT-2022-24895 · Unknown · Parse Server

·

CVE-2022-39313

·

Published

2022-10-18

·

Updated

2024-03-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Parse Server versions prior to 4.10.17 Parse Server versions prior to 5.2.8 on the 5.x branch
Description The issue occurs when a file download request is received with an invalid byte range, causing the server to crash and resulting in a Denial of Service. The problem has been patched in versions 4.10.17 and 5.2.8.
Recommendations For versions prior to 4.10.17, update to version 4.10.17 or later. For versions prior to 5.2.8 on the 5.x branch, update to version 5.2.8 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PARSE-2022-39313
CVE-2022-39313
GHSA-H423-W6QV-2WJ3

Affected Products

Parse Server