Loading HuntDB...

GHSA-236h-rqv8-8q73

GitHub Security Advisory

GraphQL: Security breach on Viewer query

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.

### Patches
This vulnerability has been patched in Parse Server 4.3.0.

### Workarounds
No

### References
See [commit 78239ac](https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa) for details.

Affected Packages

npm parse-server
Affected versions: 3.5.0 (fixed in 4.3.0)

Related CVEs

Key Information

GHSA ID
GHSA-236h-rqv8-8q73
Published
July 22, 2020 11:06 PM
Last Modified
October 26, 2023 11:33 AM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
parse-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.