CVE-2020-15126

CVE-2020-15126

In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.

Source: CVE-2020-15126

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다