Description
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
Remediation
References
https://github.com/parse-community/parse-server/security/advisories/GHSA-qf8x-vqjv-92gr
Related Vulnerabilities
CVE-2020-2253 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-10243 Vulnerability in maven package org.eclipse.kura:target-platform
CVE-2019-10395 Vulnerability in maven package org.jenkins-ci.plugins:build-environment
CVE-2020-7701 Vulnerability in npm package madlib-object-utils