9.8
CVSSv3

CVE-2019-12300

Published: 23/05/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Buildbot prior to 1.8.2 and 2.x prior to 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

buildbot buildbot

Vendor Advisories

Debian Bug report logs - #929849 buildbot: CVE-2019-12300: OAuth vulnerability in using submitted authorization token for authentication Package: src:buildbot; Maintainer for src:buildbot is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg&g ...