www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
References
Link | Resource |
---|---|
https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code | Exploit Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-03 08:29
Updated : 2024-02-04 20:03
NVD link : CVE-2019-7313
Mitre link : CVE-2019-7313
CVE.ORG link : CVE-2019-7313
JSON object : View
Products Affected
buildbot
- buildbot
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')