CVE-2019-11218
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- bonobogitserver/bonobo git server
- Source
- cve@mitre.org
References
- https://bonobogitserver.com/changelog/#version-650Release Notes, Third Party Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11218Third Party Advisory
- https://bonobogitserver.com/changelog/#version-650Release Notes, Third Party Advisory
- https://flab.cesnet.cz/advisories/cve-2019-11218Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.