Junglewise Threat Intelligence

CVE-2019-12300: PYSEC-2019-6 - Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an

CVE-2019-12300 · Severity: low · CVSS 3 · Published 2019-05-23

Technologies: buildbot (PyPI). Vendors: PyPI.

Executive brief

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Affected products

  • PyPI buildbot

Related threats