CVE-2024-39309
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 20.2%
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.
How to fix CVE-2024-39309
To remediate CVE-2024-39309, upgrade the affected package to a fixed version below.
- —upgrade to 7.2.0 or later
- —upgrade to 6.5.7 or later
Is CVE-2024-39309 being exploited?
Moderate — EPSS is 20.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 7.2.0
- from 0, < 6.5.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |