Medium severity4.3NVD Advisory· Published Jul 10, 2019· Updated Jun 17, 2026
CVE-2018-19582
CVE-2018-19582
Description
GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- GitLab/GitLab EEdescription
- Range: 11.4 < 11.4.8, 11.5 < 11.5.1
Patches
Vulnerability mechanics
References
2- about.gitlab.com/2018/11/28/security-release-gitlab-11-dot-5-dot-1-released/nvdRelease NotesVendor Advisory
- gitlab.com/gitlab-org/gitlab-ee/issues/8180nvdVendor Advisory
News mentions
0No linked articles in our index yet.