Issue
Two specs in spec/vulnerabilities.spec.js create a Parse.LiveQueryClient with serverURL: 'ws://localhost:1337'. The test server runs its LiveQuery server on the Parse Server port 8378 (startLiveQueryServer: true without liveQueryServerOptions.port), and nothing listens on port 1337. So these clients never connect, and the specs pass without their subscriptions reaching the server:
(GHSA-mf3j-86qx-cq5j) ReDoS via $regex in LiveQuery subscription > does not block event loop with catastrophic backtracking regex in LiveQuery expects the LiveQuery event to time out. It also times out if the server doesn't protect against the regex, so the spec doesn't test the protection.
(GHSA-fjxm-vhvc-gcmj) LiveQuery Operator Type Confusion > LiveQuery integration > server does not crash and other subscriptions work when type-confused subscription exists subscribes with a malformed query through such a client, so the malformed query never reaches the server.
These clients also keep reconnecting for the rest of the test run, because LiveQueryClient.close() doesn't cancel a pending reconnect (parse-community/Parse-SDK-JS#3138).
Found by reading the code; the specs were not run or changed for this.
Issue
Two specs in
spec/vulnerabilities.spec.jscreate aParse.LiveQueryClientwithserverURL: 'ws://localhost:1337'. The test server runs its LiveQuery server on the Parse Server port 8378 (startLiveQueryServer: truewithoutliveQueryServerOptions.port), and nothing listens on port 1337. So these clients never connect, and the specs pass without their subscriptions reaching the server:(GHSA-mf3j-86qx-cq5j) ReDoS via $regex in LiveQuery subscription>does not block event loop with catastrophic backtracking regex in LiveQueryexpects the LiveQuery event to time out. It also times out if the server doesn't protect against the regex, so the spec doesn't test the protection.(GHSA-fjxm-vhvc-gcmj) LiveQuery Operator Type Confusion>LiveQuery integration>server does not crash and other subscriptions work when type-confused subscription existssubscribes with a malformed query through such a client, so the malformed query never reaches the server.These clients also keep reconnecting for the rest of the test run, because
LiveQueryClient.close()doesn't cancel a pending reconnect (parse-community/Parse-SDK-JS#3138).Found by reading the code; the specs were not run or changed for this.