Junglewise Threat Intelligence

PYSEC-2019-76 - Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an

Severity: info · Published 2019-05-23

Technologies: buildbot (PyPI). Vendors: PyPI.

Executive brief

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Affected products

  • PyPI buildbot

Related threats