ZeroHour

CVE-2018-19582

CVSS 3.0
4.3 medium
EPSS
<1%p56
Published
()
Modified
Description

GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

Vendors
gitlab
Products
gitlab
Weakness
CWE-639
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.