VDB
Sign up
—

PYSEC-2019-7

Quick fix

PYSEC-2019-7 — buildbot: upgrade to the fixed version with the command below.

pip install --upgrade 'buildbot>=1.8.1'

Details

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/buildbot
Introduced in: 0.9.0Fixed in: 1.8.1
Fixpip install --upgrade 'buildbot>=1.8.1'

References