Loading HuntDB...

CRLF injection on https://buildbot.mariadb.org

Medium
M
MariaDB
Submitted None

Team Summary

Official summary from MariaDB

A CRLF (new line) injection vulnerability has been discovered in the Buildbot.net software and reported to us. We have forwarded this to the Buildbot developers which coordinated a fix release and public disclosure. This vulnerability has been assigned [CVE-2019-7313](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7313). More details in the [advisory](https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code) text.

Reported by mik317

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

CRLF Injection