296,663
Total vulnerabilities in the database
Prototype pollution capabilities on various APIs.
Injection of malicious payload allows attacker to remotely execute arbitrary code. Parse.Object
and internal APIs are affected, specifically:
ParseObject.fromJSON
ParseObject.pin
ParseObject.registerSubclass
ObjectStateMutations
(internal)encode
/decode
(internal)Demonstrative tests added as part of the fix.
Software | From | Fixed in |
---|---|---|
![]() |
- | 7.0.0 |