GHSA-66x7-2r56-fj77
Dashboard / Vulnerabilities / GHSA-66x7-2r56-fj77
GHSA-66x7-2r56-fj77
Summary: Buildbot CRLF Injection
Details: `www/resource.py` in Buildbot before 1.8.1 allows CRLF injection in the Location header of `/auth/login` and `/auth/logout` via the redirect parameter. This affects other web sites in the same domain.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-7313, https://github.com/buildbot/buildbot/pull/4584, https://github.com/buildbot/buildbot/commit/e781f110933e05ecdb30abc64327a2c7c9ff9c5a, https://github.com/buildbot/buildbot, https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code, https://github.com/pypa/advisory-database/tree/main/vulns/buildbot/PYSEC-2019-7.yaml
Affected packages
Package
Name: buildbot
Purl: pkg:pypi/buildbot
Affected ranges
Type: ECOSYSTEM
Events:
