www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
References
Link | Resource |
---|---|
https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code | Exploit Patch Third Party Advisory |
https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code | Exploit Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 04:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-codeĀ - Exploit, Patch, Third Party Advisory |
Information
Published : 2019-02-03 08:29
Updated : 2024-11-21 04:47
NVD link : CVE-2019-7313
Mitre link : CVE-2019-7313
CVE.ORG link : CVE-2019-7313
JSON object : View
Products Affected
buildbot
- buildbot
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')