GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.
References
Link | Resource |
---|---|
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/ | Release Notes Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab-ee/issues/8180 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-10T16:45:43
Updated: 2019-07-10T16:45:43
Reserved: 2018-11-26T00:00:00
Link: CVE-2018-19582
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-07-10T17:15:11.850
Modified: 2020-08-24T17:37:01.140
Link: CVE-2018-19582
JSON object: View
Redhat Information
No data.
CWE