CVE-2019-11218
Last modified
CVE-2019-11218 is a vulnerability of currently unknown severity. Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bonobogitserver | Bonobo Git Server | < 6.5.0 |
References
- https://bonobogitserver.com/changelog/#version-650Release Notes, Third Party Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11218Third Party Advisory
- https://bonobogitserver.com/changelog/#version-650Release Notes, Third Party Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11218Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11218?
How severe is CVE-2019-11218?
How do I fix CVE-2019-11218?
Are you affected by CVE-2019-11218?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
