← Back

CVE-2018-19582

nvd nist
Published: Jul 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

Affected (2)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 11.4.0 to 11.4.8
From 11.5.0 to 11.5.1

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.