CVE-2019-11218: Input Validation
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11218?
CVE-2019-11218 is categorized as a medium severity vulnerability due to the potential for authenticated users to escalate their privileges.
How do I fix CVE-2019-11218?
To fix CVE-2019-11218, update Bonobo Git Server to version 6.5.0 or later.
Who is affected by CVE-2019-11218?
CVE-2019-11218 affects all versions of Bonobo Git Server prior to 6.5.0.
What type of vulnerability is CVE-2019-11218?
CVE-2019-11218 is an improper handling vulnerability related to the AccountController in Bonobo Git Server.
Can CVE-2019-11218 allow unauthorized access?
CVE-2019-11218 can allow authenticated users to gain application administrator privileges, which could lead to unauthorized access.