Trigger `beforeFind` not invoked in internal query pipeline in parse-server
CVE-2023-41058
What is CVE-2023-41058?
In certain versions of Parse Server, an improper handling of the beforeFind Cloud trigger allows certain queries to bypass security checks. This vulnerability can expose applications that rely on this trigger to control query modifications, potentially leading to unauthorized data access. To mitigate this risk, users should upgrade to versions 5.5.5 or 6.2.2 where this issue has been addressed. For those unable to upgrade, it's recommended to utilize the built-in security features, such as Class-Level Permissions and Object-Level Access Control, instead of relying solely on custom security mechanisms within Cloud Code triggers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parse-server >= 1.0.0, < 5.5.5 < 1.0.0, 5.5.5
parse-server >= 6.0.0, < 6.2.2 < 6.0.0, 6.2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
