Password Hardcoded |
A hardcoded password in plain text was identified. Store it properly in a config file. |
218 |
src/PromiseRouter.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
190 |
src/middlewares.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
49 |
src/cryptoUtils.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
13 |
src/Controllers/PushController.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
src/Routers/IAPValidationRouter.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
17 |
src/LiveQuery/ParseWebSocketServer.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
39 |
src/Adapters/Cache/InMemoryCache.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
1084 |
src/Adapters/Storage/Postgres/PostgresStorageAdapter.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
35 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
39 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
44 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
49 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
53 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
57 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
67 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
134 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
140 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
188 |
src/Adapters/Storage/Mongo/MongoTransform.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
255 |
src/Adapters/Storage/Mongo/MongoTransform.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/Parse.Push.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
6 |
spec/ParseFile.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
spec/PushRouter.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
28 |
spec/ParseWebSocketServer.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
8 |
spec/RestCreate.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
spec/EmailVerificationToken.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
33 |
spec/EmailVerificationToken.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
74 |
spec/EmailVerificationToken.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
465 |
spec/EmailVerificationToken.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
6 |
spec/CacheController.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
spec/PublicAPI.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
10 |
spec/ParseInstallation.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
167 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
186 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
220 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
249 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
269 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
305 |
spec/CloudCode.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
427 |
spec/CloudCode.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
10 |
spec/ParseUser.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
spec/schemas.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
285 |
spec/PushController.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/ParseGlobalConfig.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
11 |
spec/InMemoryCache.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
19 |
spec/InMemoryCache.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/Uniqueness.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/LogsRouter.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
5 |
spec/WinstonLoggerAdapter.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
4 |
spec/InMemoryCacheAdapter.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
9 |
spec/InMemoryCacheAdapter.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
spec/ValidationAndPasswordsReset.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
129 |
spec/ValidationAndPasswordsReset.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
176 |
spec/ValidationAndPasswordsReset.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/ParseHooks.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
480 |
spec/ParseHooks.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
spec/features.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
448 |
spec/ParseLiveQueryServer.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
483 |
spec/ParseLiveQueryServer.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
520 |
spec/ParseLiveQueryServer.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
553 |
spec/ParseLiveQueryServer.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
590 |
spec/ParseLiveQueryServer.spec.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
623 |
spec/ParseLiveQueryServer.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
9 |
spec/RestQuery.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
1 |
spec/PurchaseValidation.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
6 |
spec/ParseAPI.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
spec/OAuth.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
46 |
spec/OAuth.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
73 |
spec/OAuth.spec.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
spec/index.spec.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
47 |
spec/index.spec.js |