-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing prototype pollution checks in MongoDB operation handlers. Key evidence comes from patches adding Utils.checkProhibitedKeywords calls to DatabaseController's create/update methods and FilesRouter's file handling. The removed RestWrite.checkProhibitedKeywords indicates prior validation was insufficient. These functions directly process user input that could contain malicious BSON payloads. Runtime detection would focus on database operations and file handling paths before security checks were added.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| parse-server | npm | < 5.5.2 | 5.5.2 |
| parse-server | npm | >= 6.0.0, < 6.2.1 | 6.2.1 |
KEV Misses 88% of Exploited CVEs- Get the report