Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g86p-hgx5-2pfh

Опубликовано: 29 мая 2019
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Improper Authentication in Buildbot

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Пакеты

Наименование

buildbot

pip
Затронутые версииВерсия исправления

< 1.8.2

1.8.2

Наименование

buildbot

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.3.1

2.3.1

EPSS

Процентиль: 65%
0.00499
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

CVSS3: 9.8
nvd
больше 6 лет назад

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

CVSS3: 9.8
debian
больше 6 лет назад

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted au ...

EPSS

Процентиль: 65%
0.00499
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287