Loading HuntDB...

GHSA-crrq-vr9j-fxxh

GitHub Security Advisory

Protected fields exposed via LiveQuery

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

Parse Server LiveQuery does not remove protected fields in classes, passing them to the client.

### Patches
The LiveQueryController now removes protected fields from the client response.

### Workarounds
Use `Parse.Cloud.afterLiveQueryEvent` to manually remove protected fields.

### References
- https://github.com/parse-community/parse-server/security/advisories/GHSA-crrq-vr9j-fxxh
- https://github.com/parse-community/parse-server

### For more information
If you have any questions or comments about this advisory:
- For questions or comments about this vulnerability visit our [community forum](http://community.parseplatform.org/) or [community chat](http://chat.parseplatform.org/)
- Report other vulnerabilities at [report.parseplatform.org](https://report.parseplatform.org/)

Affected Packages

npm parse-server
Affected versions: 0 (fixed in 4.10.13)
npm parse-server
Affected versions: 5.0.0 (fixed in 5.2.4)

Related CVEs

Key Information

GHSA ID
GHSA-crrq-vr9j-fxxh
Published
July 6, 2022 7:52 PM
Last Modified
July 6, 2022 7:52 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
parse-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.