CRLF injection Affecting buildbot package, versions [,1.8.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about CRLF injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-BUILDBOT-73642
  • published3 Feb 2019
  • disclosed29 Jan 2019
  • creditMichele Romano (mik317)

Introduced: 29 Jan 2019

CVE-2019-7313  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade buildbot to version 1.8.1 or higher.

Overview

buildbot is a continuous integration framework for automating software build, test, and release processes.

Affected versions of this package are vulnerable to CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

CVSS Scores

version 3.1