PT-2019-12741 · Buildbot+1 · Buildbot+1

Phillip Kuhrt

·

Published

2019-05-23

·

Updated

2025-01-05

·

CVE-2019-12300

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buildbot versions prior to 1.8.2 Buildbot versions 2.x prior to 2.3.1
Description The issue allows an attacker to login as a victim if they have a token that permits them to read the victim's user details. This is possible because Buildbot accepts and uses user-submitted authorization tokens from OAuth for authentication.
Recommendations For Buildbot versions prior to 1.8.2, update to version 1.8.2 or later. For Buildbot versions 2.x prior to 2.3.1, update to version 2.3.1 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1639
ALT-PU-2024-17789
CVE-2019-12300
GHSA-G86P-HGX5-2PFH
PYSEC-2019-6

Affected Products

Alt Linux
Buildbot