Back to overview

CVE-2021-47987

HIGH
7.5
CVSS 3.1
Description
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.

Metadata

CVE ID
CVE-2021-47987
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-21 02:08 UTC
Published
2026-06-25 21:41 UTC
Last updated
2026-06-25 21:41 UTC
Primary CWE
CWE-494
Download of Code Without Integrity Check
Vendor / Product
parse-community / parse-server
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
parse-community parse-server 0 < 4.10.0, 4.10.0
Weakness (CWE)
CWESourceDescription
CWE-494 cna Download of Code Without Integrity Check
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References (2)
Back to overview