SCA: security update for parse-dashboard (GHSA-jhp4-jvq3-w5xr)

high Tenable Self-Hosted Container Security Plugin ID 438033

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42
through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only
master key when resolving function-typed keys. Under specific timing conditions, a read-only user can
receive the cached full master key, or a regular user can receive the cached read-only master key. The fix
in version 9.0.0-alpha.8 uses distinct cache keys for master key and read-only master key. As a
workaround, avoid using function-typed master keys, or remove the `agent` configuration block from your
dashboard configuration. (CVE-2026-27610)

See Also

https://github.com/advisories/GHSA-jhp4-jvq3-w5xr

Plugin Details

Severity: High

ID: 438033

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 3/2/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-27610

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7

Threat Score: 3.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/25/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-27610