{"id":"CVE-2019-7313","aliases":["GHSA-66x7-2r56-fj77","PYSEC-2019-7"],"url":"https://o3.security/vulnerability/CVE-2019-7313","summary":"Buildbot CRLF Injection","details":"www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.","published":"2019-02-03T08:29:00.480Z","modified":"2026-07-08T16:08:27.383894Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"buildbot","fixedVersion":"1.8.1"}],"fix":{"url":"https://github.com/buildbot/buildbot/pull/4584","label":"buildbot/buildbot#4584"},"references":[{"type":"FIX","url":"https://github.com/buildbot/buildbot/wiki/CRLF-injection-in-Buildbot-login-and-logout-redirect-code"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7313"},{"type":"WEB","url":"https://github.com/buildbot/buildbot/pull/4584"},{"type":"WEB","url":"https://github.com/buildbot/buildbot/commit/e781f110933e05ecdb30abc64327a2c7c9ff9c5a"},{"type":"PACKAGE","url":"https://github.com/buildbot/buildbot"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/buildbot/PYSEC-2019-7.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:08:27.383894Z"}}