Security Advisory

CVE-2019-7313

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-02-03 08:00:00
Last updated 2024-09-16 23:21:39
Assigner mitre
State PUBLISHED

Description

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.