Skip to content
Noroxi

buildbot records

4 published records for vendor buildbot.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user.

    CriticalCVSS 9.8No exploitEPSS 2%

    buildbot · buildbotMay 23, 2019

  • CVE-2019-7313
    24Monitor

    www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect param

    MediumCVSS 6.1No exploitEPSS 1%

    buildbot · buildbotFeb 3, 2019

  • CVE-2009-2967
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 2%

    buildbot · buildbotAug 26, 2009

  • CVE-2009-2959
    18Monitor

    Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allow

    MediumCVSS 4.3No exploitEPSS 2%

    buildbot · buildbotAug 25, 2009