Количество 4
Количество 4
CVE-2019-12300
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.
CVE-2019-12300
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.
CVE-2019-12300
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted au ...
GHSA-g86p-hgx5-2pfh
Improper Authentication in Buildbot
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-12300 Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim. | CVSS3: 9.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-12300 Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim. | CVSS3: 9.8 | 0% Низкий | больше 6 лет назад | |
CVE-2019-12300 Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted au ... | CVSS3: 9.8 | 0% Низкий | больше 6 лет назад | |
GHSA-g86p-hgx5-2pfh Improper Authentication in Buildbot | CVSS3: 9.8 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу