GHSA-crrq-vr9j-fxxh
GitHub Security Advisory
Protected fields exposed via LiveQuery
Advisory Details
### Impact
Parse Server LiveQuery does not remove protected fields in classes, passing them to the client.
### Patches
The LiveQueryController now removes protected fields from the client response.
### Workarounds
Use `Parse.Cloud.afterLiveQueryEvent` to manually remove protected fields.
### References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-crrq-vr9j-fxxh
- https://github.com/parse-community/parse-server
### For more information
If you have any questions or comments about this advisory:
- For questions or comments about this vulnerability visit our [community forum](http://community.parseplatform.org/) or [community chat](http://chat.parseplatform.org/)
- Report other vulnerabilities at [report.parseplatform.org](https://report.parseplatform.org/)
Affected Packages
Related CVEs
Key Information
Dataset
Data from GitHub Advisory Database. This information is provided for research and educational purposes.