Unauthenticated account takeover via regex token queries
Published Mar 4, 2020 · Updated Aug 4, 2024
Incorrect authorization in Parse Platform Parse Server before 4.1.0 allows remote attackers to discover valid accounts through crafted NoSQL queries. Session-token middleware and public email-verification and password-reset handlers accept object-valued token input, allowing a supplied $regex operator to reach database comparisons instead of enforcing an exact string token. No prior authentication or user interaction is required; repeated matches disclose user objects and enable account verification or password reset for another username.
Summary
What happened
Incorrect authorization in Parse Platform Parse Server before 4.1.0 allows remote attackers to discover valid accounts through crafted NoSQL queries. Session-token middleware and public email-verification and password-reset handlers accept object-valued token input, allowing a supplied $regex operator to reach database comparisons instead of enforcing an exact string token. No prior authentication or user interaction is required; repeated matches disclose user objects and enable account verification or password reset for another username.
The record
- CVE
- CVE-2020-5251
- Published
- Mar 4, 2020
- Updated
- Aug 4, 2024
- Vendor
- Parse Platform
- Product
- Parse Server
- Classifications
- CWE-863, CWE-285, T1528
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Mar 4, 2020CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=< 4.1.0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GHSA regex token request examplesproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo