{"id":"GHSA-8xq9-g7ch-35hg","summary":"Parse Server's custom object ID allows to acquire role privileges","details":"### Impact\n\nIf the Parse Server option `allowCustomObjectId: true` is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role.\n\n### Patches\n\nImproved validation for custom user object IDs. Session tokens for existing users with an object ID that exploits the vulnerability are now rejected.\n\n### Workarounds\n\n- Disable custom object IDs by setting `allowCustomObjectId: false` or not setting the option which defaults to `false`.\n- Use a Cloud Code Trigger to validate that a new user's object ID doesn't start with the prefix `role:`.\n\n### References\n\n- https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg\n- https://github.com/parse-community/parse-server/pull/9317 (fix for Parse Server 7)\n- https://github.com/parse-community/parse-server/pull/9318 (fix for Parse Server 6)","aliases":["BIT-parse-2024-47183","CVE-2024-47183"],"modified":"2024-10-08T08:11:52.830021Z","published":"2024-10-04T18:50:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-10-04T18:50:56Z","nvd_published_at":"2024-10-04T15:15:13Z","cwe_ids":["CWE-285","CWE-863"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-8xq9-g7ch-35hg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47183"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/9317"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/pull/9318"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/13ee52f0d19ef3a3524b3d79aea100e587eb3cfc"},{"type":"WEB","url":"https://github.com/parse-community/parse-server/commit/1bfbccf9ee7ea77533b2b2aa7c4c69f3bd35e66f"},{"type":"PACKAGE","url":"https://github.com/parse-community/parse-server"}],"affected":[{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.5.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json"}},{"package":{"name":"parse-server","ecosystem":"npm","purl":"pkg:npm/parse-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}