CVE Vulnerabilities

CVE-2019-7313

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Feb 03, 2019 | Modified: Feb 06, 2019
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

Name Vendor Start Version End Version
Buildbot Buildbot 0.9.0 (including) 1.8.0 (including)
Buildbot Ubuntu bionic *
Buildbot Ubuntu cosmic *
Buildbot Ubuntu devel *
Buildbot Ubuntu disco *
Buildbot Ubuntu eoan *
Buildbot Ubuntu esm-apps/bionic *
Buildbot Ubuntu focal *
Buildbot Ubuntu groovy *
Buildbot Ubuntu hirsute *
Buildbot Ubuntu impish *
Buildbot Ubuntu jammy *
Buildbot Ubuntu kinetic *
Buildbot Ubuntu lunar *
Buildbot Ubuntu mantic *
Buildbot Ubuntu noble *
Buildbot Ubuntu oracular *
Buildbot Ubuntu upstream *

Potential Mitigations

References