Skip to content

Two LiveQuery security specs never connect to the LiveQuery server #10720

Description

@mtrezza

Issue

Two specs in spec/vulnerabilities.spec.js create a Parse.LiveQueryClient with serverURL: 'ws://localhost:1337'. The test server runs its LiveQuery server on the Parse Server port 8378 (startLiveQueryServer: true without liveQueryServerOptions.port), and nothing listens on port 1337. So these clients never connect, and the specs pass without their subscriptions reaching the server:

  • (GHSA-mf3j-86qx-cq5j) ReDoS via $regex in LiveQuery subscription > does not block event loop with catastrophic backtracking regex in LiveQuery expects the LiveQuery event to time out. It also times out if the server doesn't protect against the regex, so the spec doesn't test the protection.
  • (GHSA-fjxm-vhvc-gcmj) LiveQuery Operator Type Confusion > LiveQuery integration > server does not crash and other subscriptions work when type-confused subscription exists subscribes with a malformed query through such a client, so the malformed query never reaches the server.

These clients also keep reconnecting for the rest of the test run, because LiveQueryClient.close() doesn't cancel a pending reconnect (parse-community/Parse-SDK-JS#3138).

Found by reading the code; the specs were not run or changed for this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions