CVE-2025-30168
CVSS 3.1 Score 6.9 of 10 (medium)
Details
Summary
CVE-2025-30168 is a vulnerability affecting Parse Server, an open-source Node.js backend. Prior to version 7.5.2 and 8.0.2, the platform's third-party authentication handling was found to be insecure. This issue allows authentication credentials from specific providers to be shared across multiple Parse Server applications. For instance, a user signing up with the same authentication provider in two unrelated apps could lead to the credentials from one app being utilized to authenticate the same user in the other. Only Parse Server apps using an affected third-party authentication provider for user authentication are vulnerable. To mitigate this vulnerability, it's necessary to upgrade both the Parse Server and the client app, as the latter must also send a secure payload instead of the previous insecure one. Versions 7.5.2 and 8.0.2 of Parse Server contain the necessary bug fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Parse Server
Affected Vendors
- Parse