CVE-2018-19582
Summary
| CVE | CVE-2018-19582 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-10 17:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user. |
Risk And Classification
Problem Types: CWE-639
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitLab Security Release: 11.5.1, 11.4.8, and 11.3.11 | GitLab | CONFIRM | about.gitlab.com | Release Notes, Vendor Advisory |
| IDOR at /drafts/publish/ (#8180) · Issues · GitLab.org / GitLab · GitLab | MISC | gitlab.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.