VYPR
Medium severity6.5OSV Advisory· Published Feb 4, 2019· Updated Jun 17, 2026

CVE-2019-1000011

CVE-2019-1000011

Description

API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed in 2.3.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
api-platform/corePackagist
>= 2.2.0, < 2.2.102.2.10
api-platform/corePackagist
>= 2.3.0, < 2.3.62.3.6

Affected products

3
  • API Platform/CoreOSV2 versions
    push, remove, v2.2.0, …+ 1 more
    • (no CPE)range: push, remove, v2.2.0, …
    • cpe:2.3:a:api-platform:core:*:*:*:*:*:*:*:*range: >=2.2.0,<=2.3.5
  • ghsa-coords
    Range: >= 2.2.0, < 2.2.10

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.