{"id":"CVE-2019-1000011","aliases":["GHSA-974j-wjxx-wggj"],"url":"https://o3.security/vulnerability/CVE-2019-1000011","summary":"Incorrect Access Control vulnerability in api-platform/core","details":"API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed in 2.3.6.","published":"2019-02-04T21:29:01.050Z","modified":"2026-08-07T15:00:13.633349Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.01147,"percentile":0.63877,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"api-platform/core","fixedVersion":"2.2.10"},{"ecosystem":"Packagist","name":"api-platform/core","fixedVersion":"2.3.6"}],"fix":{"url":"https://github.com/api-platform/core/pull/2441","label":"api-platform/core#2441"},"references":[{"type":"REPORT","url":"https://github.com/api-platform/core/issues/2364"},{"type":"REPORT","url":"https://github.com/api-platform/core/pull/2441"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:00:13.633349Z"}}