Medium severity6.5OSV Advisory· Published Feb 4, 2019· Updated Jun 17, 2026
CVE-2019-1000011
CVE-2019-1000011
Description
API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed in 2.3.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
api-platform/corePackagist | >= 2.2.0, < 2.2.10 | 2.2.10 |
api-platform/corePackagist | >= 2.3.0, < 2.3.6 | 2.3.6 |
Affected products
3push, remove, v2.2.0, …+ 1 more
- (no CPE)range: push, remove, v2.2.0, …
- cpe:2.3:a:api-platform:core:*:*:*:*:*:*:*:*range: >=2.2.0,<=2.3.5
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-974j-wjxx-wggjghsaADVISORY
- github.com/api-platform/core/issues/2364nvdIssue TrackingThird Party AdvisoryWEB
- github.com/api-platform/core/pull/2441nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-1000011ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/api-platform/core/CVE-2019-1000011.yamlghsaWEB
News mentions
0No linked articles in our index yet.