High
Node.js parse-server module could allow a remote attacker to obtain sensitive information, caused by not removing protected fields in classes when passing to the client. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Node.js
Node.js parse-server 4.10.12
Node.js parse-server 5.2.3
Refer to Parse Server GIT Repository for patch, upgrade or suggested workaround information.