SCA: security update for parse-server (GHSA-6hh7-46r2-vf29)

critical Tenable Self-Hosted Container Security Plugin ID 411468

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud
Job name crashes the server and may allow for code injection, internal store manipulation or remote code
execution. The patch in versions 6.5.5 and 7.0.0-alpha.29 added string sanitation for Cloud Function name
and Cloud Job name. As a workaround, sanitize the Cloud Function name and Cloud Job name before it reaches
Parse Server. (CVE-2024-29027)

See Also

https://github.com/advisories/GHSA-6hh7-46r2-vf29

Plugin Details

Severity: Critical

ID: 411468

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.45

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-29027

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 7.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/19/2024

Vulnerability Publication Date: 3/19/2024

Reference Information

CVE: CVE-2024-29027