PT-2019-11264 · Symfony · Api Platform

Skvokeno

·

Publicado

2019-02-04

·

Atualizado

2020-08-24

·

CVE-2019-1000011

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: API Platform versions 2.2.0 through 2.3.5
Description: The issue is related to an Incorrect Access Control vulnerability in GraphQL delete mutations. This allows a user who is authorized to delete a resource to delete any resource. The attack is exploitable if the user has authorization.
Recommendations: For API Platform versions 2.2.0 through 2.3.5, update to version 2.3.6 to resolve the issue.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1000011
GHSA-974J-WJXX-WGGJ

Produtos afetados

Api Platform