PT-2019-12194 · Bonobo · Bonobo Git Server

Publicado

2019-04-24

·

Atualizado

2021-07-21

·

CVE-2019-11218

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bonobo Git Server versions prior to 6.5.0
Description The issue arises from improper handling of extra parameters in the AccountController, specifically in the User Profile edit functionality. This allows authenticated users to submit additional form parameters and potentially gain application administrator privileges.
Recommendations For versions prior to 6.5.0, update to version 6.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the User Profile edit functionality in the AccountController to prevent potential exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11218

Produtos afetados

Bonobo Git Server