buildbot kayıtları
buildbot üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-12300İstismar yok | Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user.buildbot · buildbot · CWE-287 | Kritik9,8 | — | %1,8 | 23 May 2019 |
24İzleyin | CVE-2019-7313İstismar yok | www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parambuildbot · buildbot · CWE-93 | Orta6,1 | — | %0,9 | 3 Şub 2019 |
18İzleyin | CVE-2009-2967İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web scriptbuildbot · buildbot · CWE-79 | Orta4,3 | — | %2,3 | 26 Ağu 2009 |
18İzleyin | CVE-2009-2959İstismar yok | Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allowbuildbot · buildbot · CWE-79 | Orta4,3 | — | %2,0 | 25 Ağu 2009 |
- CVE-2019-1230040Planlayın
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user.
KritikCVSS 9,8İstismar yokEPSS %2buildbot · buildbot23 May 2019
- CVE-2019-731324İzleyin
www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect param
OrtaCVSS 6,1İstismar yokEPSS %1buildbot · buildbot3 Şub 2019
- CVE-2009-296718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script
OrtaCVSS 4,3İstismar yokEPSS %2buildbot · buildbot26 Ağu 2009
- CVE-2009-295918İzleyin
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allow
OrtaCVSS 4,3İstismar yokEPSS %2buildbot · buildbot25 Ağu 2009