CVE-2018-19582

NameCVE-2018-19582
DescriptionGitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gitlabunknown(unstable)(not affected)

Notes

- gitlab <not-affected> (Specific to Enterprise edition)
https://about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/

Search for package or bug name: Reporting problems