OVERVIEW
Lab observed
Vendor reported
Vendor-reported fixed versions
18.11.11 / 19.0.8 / 19.1.6 / 19.2.4Only the lab versions above were independently reproduced by CVE Mapping.
LAB OBSERVED
What this lab demonstrates
The lab reproduced a state-changing GET /api/graphql multiplex request as Victim on 19.2.2-ee.0 and observed no corresponding state change in the same general test pattern on 19.2.4-ee.0.
Vulnerable baseline passed, the disposable proof issue was found as the synthetic Victim, and the patched control returned no unique proof issue. Application state—not HTTP 200 alone—is decisive.
VULNERABLE VS PATCHED RESULT
Runtime accepted and state change observed.
Runtime accepted and unique proof issue absent.
Repository validation is marked true in the manifest.
DETECTION COVERAGE
Detection engineering
- Sigmalab-validated
- Splunklab-validated
- Elasticlab-validated
- osquerysupporting
EVIDENCE & TELEMETRY
Preserved and verifiable
Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.
REPRODUCE LOCALLY
Start with the Quickstart.
Use the repository operator workflow on a disposable, localhost-only environment. The website does not embed the browser proof payload.
Open QuickstartLIMITATIONS & SAFETY
Scope stays explicit.
The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and no automated exploit command.