www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
References
Link | Resource |
---|---|
https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2019-02-03 00:29
Updated : 2019-02-06 13:48
NVD link : CVE-2019-7313
Mitre link : CVE-2019-7313
JSON object : View
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Products Affected
buildbot
- buildbot