PT-2026-61927 · Unknown · Parse Server
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Parse Server versions 9.0.0 through 9.10.0-alpha.3
Parse Server versions prior to 8.6.85
Description
A schema disclosure issue exists when the GraphQL API is configured with
graphQLPublicIntrospection set to false. Error messages generated during variable coercion continue to provide schema-derived suggestions, bypassing the introspection-hardening control. An unauthenticated user with the public application id can iteratively recover hidden schema identifiers, such as Parse class and field names and registered Cloud Code function names, by submitting queries or mutations with near-miss enum values or input-object field names.Recommendations
Update to version 9.10.0-alpha.4 or later.
Update to version 8.6.85 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parse Server