PT-2019-12741 · Buildbot+1 · Buildbot+1

Phillip Kuhrt

·

Publicado

2019-05-23

·

Atualizado

2025-01-05

·

CVE-2019-12300

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buildbot versions prior to 1.8.2 Buildbot versions 2.x prior to 2.3.1
Description The issue allows an attacker to login as a victim if they have a token that permits them to read the victim's user details. This is possible because Buildbot accepts and uses user-submitted authorization tokens from OAuth for authentication.
Recommendations For Buildbot versions prior to 1.8.2, update to version 1.8.2 or later. For Buildbot versions 2.x prior to 2.3.1, update to version 2.3.1 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1639
ALT-PU-2024-17789
CVE-2019-12300
GHSA-G86P-HGX5-2PFH
PYSEC-2019-6

Produtos afetados

Alt Linux
Buildbot