Advisories for Pypi/Buildbot package

2019

Authentication bypass

Buildbot accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can log in as the victim.