Description
parse-server before 3.6.0 allows account enumeration.
Remediation
References
https://github.com/parse-community/parse-server/security/advisories/GHSA-8w3j-g983-8jh5
Related Vulnerabilities
CVE-2018-19360 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-3722 Vulnerability in maven package org.webjars.npm:merge-deep
CVE-2021-41249 Vulnerability in npm package graphql-playground-react
CVE-2020-5263 Vulnerability in npm package auth0-js
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_2.12