Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12300

Опубликовано: 23 мая 2019
Источник: debian

Описание

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
buildbotfixed2.0.1-2package
buildbotnot-affectedstretchpackage
buildbotnot-affectedjessiepackage

Примечания

  • https://github.com/buildbot/buildbot/wiki/OAuth-vulnerability-in-using-submitted-authorization-token-for-authentication

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

CVSS3: 9.8
nvd
больше 6 лет назад

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

CVSS3: 9.8
github
больше 6 лет назад

Improper Authentication in Buildbot