CVE-2009-2967: Buildbot vulnerable to cross-site scripting
(updated )
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.
References
- exchange.xforce.ibmcloud.com/vulnerabilities/52896
- github.com/advisories/GHSA-mj3x-wprp-mvj9
- github.com/buildbot/buildbot
- github.com/buildbot/buildbot/commit/78f7942b5056ab75c27f491b6fd6f266699c15e3
- github.com/pypa/advisory-database/tree/main/vulns/buildbot/PYSEC-2009-2.yaml
- nvd.nist.gov/vuln/detail/CVE-2009-2967
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00978.html
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00985.html
Detect and mitigate CVE-2009-2967 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →