VDB
Sign up
—

PYSEC-2019-6

Quick fix

PYSEC-2019-6 — buildbot: upgrade to the fixed version with the command below.

pip install --upgrade 'buildbot>=1.8.2'

Details

Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/buildbot
Introduced in: 0Fixed in: 1.8.2
Fixpip install --upgrade 'buildbot>=1.8.2'

References