Description
parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload. This issue has been patched in version 4.1.3.
Remediation
References
https://github.com/parse-community/parse-server-push-adapter/pull/217
https://github.com/parse-community/parse-server-push-adapter/releases/tag/4.1.3
https://github.com/parse-community/parse-server-push-adapter/security/advisories/GHSA-mxhg-rvwx-x993
Related Vulnerabilities
CVE-2023-0091 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2023-50774 Vulnerability in maven package org.jenkins-ci.plugins:htmlresource
CVE-2023-26920 Vulnerability in npm package fast-xml-parser
CVE-2023-27898 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2016-1000352 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on