Improper Authentication in Buildbot
Critical severity
GitHub Reviewed
Published
May 29, 2019
to the GitHub Advisory Database
•
Updated Sep 13, 2024
Description
Published by the National Vulnerability Database
May 23, 2019
Reviewed
May 29, 2019
Published to the GitHub Advisory Database
May 29, 2019
Last updated
Sep 13, 2024
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.
References