CVE-2019-11218
Summary
| CVE | CVE-2019-11218 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-24 20:29:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bonobogitserver | Bonobo Git Server | All | All | All | All |
| Application | Bonobogitserver | Bonobo Git Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-11218: Privilege escalation in Bonobo Git Server AccountController [FLAB] | MISC | flab.cesnet.cz | Third Party Advisory |
| Bonobo Git Server - Changelog | CONFIRM | bonobogitserver.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.