www/ in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.

Don't forget to share

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *