Overview
parse-server
is an open source backend that can be deployed to any infrastructure that can run Node.js. In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.
Remediation
Upgrade to version 4.5.0 or later.
Resources
Have content suggestions? Send them to [email protected]
Advisory timeline
published
Advisory PublishedDec 30th, 2020reported
Reported by AnonymousDec 30th, 2020