← Back to CVE List

CVE-2020-26288

Published: 2020-12-30T20:15Z
Last Modified: 2024-11-21T05:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt