QID 981781
QID 981781: Python (pip) Security Update for buildbot (GHSA-g86p-hgx5-2pfh)
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g86p-hgx5-2pfh for updates pertaining to this vulnerability.
Vendor References
- GHSA-g86p-hgx5-2pfh -
github.com/advisories/GHSA-g86p-hgx5-2pfh
CVEs related to QID 981781
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g86p-hgx5-2pfh | buildbot |
|