CVE-2019-12300: Buildbot
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.
Affected products
- Buildbot Buildbot: before 1.8.2 (fixed in 1.8.2); from 2.0.0, before 2.3.1 (fixed in 2.3.1)
Published 2019-05-23. Last modified 2026-06-17.