Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3001 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0. |
Github GHSA |
GHSA-8xq9-g7ch-35hg | Parse Server's custom object ID allows to acquire role privileges |
Wed, 25 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform parse-server
|
|
| CPEs | cpe:2.3:a:parseplatform:parse-server:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Parseplatform parse Server
|
Parseplatform parse-server
|
Wed, 13 Nov 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parseplatform
Parseplatform parse Server |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:parseplatform:parse_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Parseplatform
Parseplatform parse Server |
Fri, 04 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Parse Community
Parse Community parse Server |
|
| CPEs | cpe:2.3:a:parse_community:parse_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Parse Community
Parse Community parse Server |
|
| Metrics |
ssvc
|
Fri, 04 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Parse Server has user id/role name confusion with ACLs | Parse Server's custom object ID allows to acquire role privileges |
Fri, 04 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a specific role. This vulnerability is fixed in 6.5.9 and 7.3.0. | |
| Title | Parse Server has user id/role name confusion with ACLs | |
| Weaknesses | CWE-285 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-04T15:30:37.224Z
Reserved: 2024-09-19T22:32:11.963Z
Link: CVE-2024-47183
Updated: 2024-10-04T15:28:04.995Z
Status : Analyzed
Published: 2024-10-04T15:15:13.010
Modified: 2026-02-25T17:47:53.147
Link: CVE-2024-47183
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA