Invalid push request payload crashes Parse Server
CVE-2023-32688
7.5HIGH
What is CVE-2023-32688?
The Parse Server Push Notification Adapter allows the potential for Parse Server to crash when it processes an invalid push notification payload. This vulnerability stems from inadequate input validation within the adapter. To mitigate this issue, users are advised to update to version 4.1.3, in which the vulnerability has been addressed. Proper handling of the push notification data is crucial to maintain server stability and security.
Affected Version(s)
parse-server-push-adapter < 4.1.3