Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7313

Опубликовано: 03 фев. 2019
Источник: debian

Описание

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
buildbotfixed2.0.0-1package
buildbotnot-affectedstretchpackage
buildbotnot-affectedjessiepackage

Примечания

  • https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code

  • https://github.com/buildbot/buildbot/pull/4584/files#diff-a2e7e3ee5f6a1d3cd9c6abf0328c21e0

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

CVSS3: 6.1
nvd
около 7 лет назад

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

CVSS3: 6.1
github
больше 3 лет назад

Buildbot CRLF Injection