{"id":"CVE-2019-12300","aliases":["GHSA-g86p-hgx5-2pfh","PYSEC-2019-6"],"url":"https://o3.security/vulnerability/CVE-2019-12300","summary":"Improper Authentication in Buildbot","details":"Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.","published":"2019-05-23T15:30:12.623Z","modified":"2026-07-08T15:55:32.685693Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01841,"percentile":0.77951,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"buildbot","fixedVersion":"1.8.2"},{"ecosystem":"PyPI","name":"buildbot","fixedVersion":"2.3.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4XLOM2K4M4723BCLHZJEX52KJXZSEVRL/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7GXKO7OYLKBTXXXKF4VPHWT7GVYWFVYA/"},{"type":"FIX","url":"https://github.com/buildbot/buildbot/wiki/OAuth-vulnerability-in-using-submitted-authorization-token-for-authentication"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T15:55:32.685693Z"}}