mirror of
https://github.com/parse-community/parse-server
synced 2026-08-09 13:03:18 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
46761d3ae2 | ||
|
|
bba24dd827 | ||
|
|
30258be121 | ||
|
|
5f9a27fb8e | ||
|
|
297faaece4 | ||
|
|
a6e6549435 | ||
|
|
244e3431cf | ||
|
|
33c648dc81 | ||
|
|
4524c35d51 | ||
|
|
70e0cb3744 | ||
|
|
519dee9b89 | ||
|
|
897acb76a5 | ||
|
|
e5de9daa18 | ||
|
|
223fde0f31 | ||
|
|
d0a5af33ca | ||
|
|
8fe0ae7a2c | ||
|
|
5179501885 | ||
|
|
933e8226df |
@@ -1,3 +1,17 @@
|
||||
## [6.5.1](https://github.com/parse-community/parse-server/compare/6.5.0...6.5.1) (2024-03-02)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* Security upgrade @parse/push-adapter from 5.0.2 to 5.1.0 ([#8972](https://github.com/parse-community/parse-server/issues/8972)) ([bba24dd](https://github.com/parse-community/parse-server/commit/bba24dd8279ebb8e4084a5f00fbe3ab9fe6c01b4))
|
||||
|
||||
# [6.5.0](https://github.com/parse-community/parse-server/compare/6.4.0...6.5.0) (2024-03-01)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* Improve PostgreSQL injection detection; fixes security vulnerability [GHSA-6927-3vr9-fxf2](https://github.com/parse-community/parse-server/security/advisories/GHSA-6927-3vr9-fxf2) which affects Parse Server deployments using a Postgres database ([#8960](https://github.com/parse-community/parse-server/issues/8960)) ([a6e6549](https://github.com/parse-community/parse-server/commit/a6e654943536932904a69b51e513507fcf90a504))
|
||||
|
||||
# [6.4.0](https://github.com/parse-community/parse-server/compare/6.3.1...6.4.0) (2023-11-16)
|
||||
|
||||
|
||||
|
||||
Generated
+3072
-442
File diff suppressed because it is too large
Load Diff
+13
-13
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "parse-server",
|
||||
"version": "6.5.0-alpha.2",
|
||||
"version": "6.5.1",
|
||||
"description": "An express module providing a Parse-compatible API server",
|
||||
"main": "lib/index.js",
|
||||
"repository": {
|
||||
@@ -24,8 +24,8 @@
|
||||
"@graphql-tools/schema": "9.0.4",
|
||||
"@graphql-tools/utils": "8.12.0",
|
||||
"@graphql-yoga/node": "2.6.0",
|
||||
"@parse/fs-files-adapter": "1.2.2",
|
||||
"@parse/push-adapter": "5.0.2",
|
||||
"@parse/fs-files-adapter": "2.0.1",
|
||||
"@parse/push-adapter": "5.1.0",
|
||||
"bcryptjs": "2.4.3",
|
||||
"body-parser": "1.20.2",
|
||||
"commander": "10.0.1",
|
||||
@@ -33,35 +33,35 @@
|
||||
"deepcopy": "2.1.0",
|
||||
"express": "4.18.2",
|
||||
"express-rate-limit": "6.7.0",
|
||||
"follow-redirects": "1.15.2",
|
||||
"follow-redirects": "1.15.5",
|
||||
"graphql": "16.8.1",
|
||||
"graphql-list-fields": "2.0.2",
|
||||
"graphql-relay": "0.10.0",
|
||||
"graphql-tag": "2.12.6",
|
||||
"intersect": "1.0.1",
|
||||
"jsonwebtoken": "9.0.0",
|
||||
"jwks-rsa": "2.1.5",
|
||||
"jwks-rsa": "3.1.0",
|
||||
"ldapjs": "2.3.3",
|
||||
"lodash": "4.17.21",
|
||||
"lru-cache": "9.1.1",
|
||||
"lru-cache": "10.1.0",
|
||||
"mime": "3.0.0",
|
||||
"mongodb": "4.10.0",
|
||||
"mustache": "4.2.0",
|
||||
"otpauth": "9.1.2",
|
||||
"otpauth": "9.2.2",
|
||||
"parse": "4.1.0",
|
||||
"path-to-regexp": "6.2.1",
|
||||
"pg-monitor": "2.0.0",
|
||||
"pg-promise": "11.5.0",
|
||||
"pg-promise": "11.5.4",
|
||||
"pluralize": "8.0.0",
|
||||
"rate-limit-redis": "3.0.2",
|
||||
"redis": "4.6.6",
|
||||
"semver": "7.5.2",
|
||||
"redis": "4.6.13",
|
||||
"semver": "7.5.4",
|
||||
"subscriptions-transport-ws": "0.11.0",
|
||||
"tv4": "1.3.0",
|
||||
"uuid": "9.0.0",
|
||||
"winston": "3.8.2",
|
||||
"uuid": "9.0.1",
|
||||
"winston": "3.11.0",
|
||||
"winston-daily-rotate-file": "4.7.1",
|
||||
"ws": "8.13.0"
|
||||
"ws": "8.16.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@actions/core": "1.9.1",
|
||||
|
||||
+2
-2
@@ -40,8 +40,8 @@ async function config() {
|
||||
{ name: 'alpha', prerelease: true },
|
||||
{ name: 'beta', prerelease: true },
|
||||
'next-major',
|
||||
// Long-Term-Support branches; defined as GLOB pattern
|
||||
'release-+([0-9]).x.x',
|
||||
// Long-Term-Support branch of previous major version
|
||||
'release-6.x.x',
|
||||
],
|
||||
dryRun: false,
|
||||
debug: true,
|
||||
|
||||
@@ -459,3 +459,28 @@ describe('Vulnerabilities', () => {
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe('Postgres regex sanitizater', () => {
|
||||
it('sanitizes the regex correctly to prevent Injection', async () => {
|
||||
const user = new Parse.User();
|
||||
user.set('username', 'username');
|
||||
user.set('password', 'password');
|
||||
user.set('email', 'email@example.com');
|
||||
await user.signUp();
|
||||
|
||||
const response = await request({
|
||||
method: 'GET',
|
||||
url:
|
||||
"http://localhost:8378/1/classes/_User?where[username][$regex]=A'B'%3BSELECT+PG_SLEEP(3)%3B--",
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'X-Parse-Application-Id': 'test',
|
||||
'X-Parse-REST-API-Key': 'rest',
|
||||
},
|
||||
});
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.data.results).toEqual(jasmine.any(Array));
|
||||
expect(response.data.results.length).toBe(0);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -2656,7 +2656,7 @@ function literalizeRegexPart(s: string) {
|
||||
.replace(/([^\\])(\\Q)/, '$1')
|
||||
.replace(/^\\E/, '')
|
||||
.replace(/^\\Q/, '')
|
||||
.replace(/([^'])'/, `$1''`)
|
||||
.replace(/([^'])'/g, `$1''`)
|
||||
.replace(/^'([^'])/, `''$1`);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user