Description
In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.
Remediation
References
https://github.com/parse-community/parse-server/commit/3a3a5eee5ffa48da1352423312cb767de14de269
https://github.com/parse-community/parse-server/security/advisories/GHSA-h4mf-75hf-67w4
Related Vulnerabilities
CVE-2023-22621 Vulnerability in npm package @strapi/plugin-email
CVE-2020-15168 Vulnerability in maven package org.webjars.npm:node-fetch
CVE-2021-21172 Vulnerability in npm package electron
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes