GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-10T16:45:43

Updated: 2019-07-10T16:45:43

Reserved: 2018-11-26T00:00:00


Link: CVE-2018-19582

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-10T17:15:11.850

Modified: 2020-08-24T17:37:01.140


Link: CVE-2018-19582

JSON object: View

cve-icon Redhat Information

No data.

CWE