Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19582

Опубликовано: 10 июл. 2019
Источник: debian
EPSS Низкий

Описание

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gitlabnot-affectedpackage

Примечания

  • https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/

EPSS

Процентиль: 29%
0.00101
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 6 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

CVSS3: 4.3
nvd
почти 6 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

github
около 3 лет назад

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

EPSS

Процентиль: 29%
0.00101
Низкий