SCA: security update for parse-server (GHSA-6w4q-23cf-j9jp)

low Tenable Self-Hosted Container Security Plugin ID 411657

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In
versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of
another user if the session object ID is known. For example, an attacker can assign the session object to
their own user by writing to the `user` field and then read any custom fields of that session object. Note
that assigning a session to another user does not usually change the privileges of either of the two
users, and a user cannot assign their own session to another user. This issue is patched in version
4.10.15 and above, and 5.2.6 and above. To mitigate this issue in unpatched versions add a `beforeSave`
trigger to the `_Session` class and prevent writing if the requesting user is different from the user in
the session object. (CVE-2022-39225)

See Also

https://github.com/advisories/GHSA-6w4q-23cf-j9jp

Plugin Details

Severity: Low

ID: 411657

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2022-39225

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/21/2022

Vulnerability Publication Date: 9/21/2022

Reference Information

CVE: CVE-2022-39225