{"id":"GHSA-66x7-2r56-fj77","summary":"Buildbot CRLF Injection","details":"`www/resource.py` in Buildbot before 1.8.1 allows CRLF injection in the Location header of `/auth/login` and `/auth/logout` via the redirect parameter. This affects other web sites in the same domain.","aliases":["CVE-2019-7313","PYSEC-2019-7"],"modified":"2024-09-13T18:02:19.322362Z","published":"2022-05-14T01:36:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-19T21:17:46Z","nvd_published_at":"2019-02-03T08:29:00Z","cwe_ids":["CWE-93"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7313"},{"type":"WEB","url":"https://github.com/buildbot/buildbot/pull/4584"},{"type":"WEB","url":"https://github.com/buildbot/buildbot/commit/e781f110933e05ecdb30abc64327a2c7c9ff9c5a"},{"type":"PACKAGE","url":"https://github.com/buildbot/buildbot"},{"type":"WEB","url":"https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/buildbot/PYSEC-2019-7.yaml"}],"affected":[{"package":{"name":"buildbot","ecosystem":"PyPI","purl":"pkg:pypi/buildbot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.0"},{"fixed":"1.8.1"}]}],"versions":["0.9.0","0.9.0.post1","0.9.1","0.9.10","0.9.11","0.9.12","0.9.13","0.9.14","0.9.15","0.9.15.post1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","0.9.9.post1","0.9.9.post2","1.0.0","1.1.0","1.1.1","1.1.2","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-66x7-2r56-fj77/GHSA-66x7-2r56-fj77.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}