PT-2026-52608 · Unknown · Parse Server
CVE-2021-47987
·
Published
2021-09-07
·
Updated
2026-07-31
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Parse Server versions prior to 4.10.0
Description
A supply chain incident occurred where incorrect version tags were pushed to the official repository. These tags pointed to an unreviewed personal fork of a contributor who had write access. Exposure occurred only if a project defined a git-based dependency referencing one of the affected tags. Although no malicious code was identified, the code was not reviewed or approved, meaning the introduction of security vulnerabilities cannot be ruled out.
Recommendations
Update Parse Server to version 4.10.0 or later.
Avoid using git-based dependencies that reference unverified version tags.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server