{"id":"CVE-2020-5251","aliases":["BIT-parse-2020-5251","GHSA-h4mf-75hf-67w4"],"url":"https://o3.security/vulnerability/CVE-2020-5251","summary":"Information disclosure in parse-server","details":"In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.","published":"2020-03-04T15:15:13.210Z","modified":"2026-08-07T15:13:47.668146Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"parse-server","fixedVersion":"4.1.0"}],"fix":{"url":"https://github.com/parse-community/parse-server/commit/3a3a5eee5ffa48da1352423312cb767de14de269","label":"parse-community/parse-server@3a3a5ee"},"references":[{"type":"ADVISORY","url":"https://github.com/parse-community/parse-server/security/advisories/GHSA-h4mf-75hf-67w4"},{"type":"FIX","url":"https://github.com/parse-community/parse-server/commit/3a3a5eee5ffa48da1352423312cb767de14de269"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:13:47.668146Z"}}