CVE-2020-15270
Improper session expiration in Parse Server
4.3
MEDIUM
CVSS 3.1
EPSS 1.2%
Description
Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.
How to fix CVE-2020-15270
To remediate CVE-2020-15270, upgrade the affected package to a fixed version below.
- —upgrade to 4.4.0 or later
Is CVE-2020-15270 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |