www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
{
"cwe_ids": [
"CWE-93"
],
"github_reviewed": true,
"nvd_published_at": "2019-02-03T08:29:00Z",
"github_reviewed_at": "2023-07-19T21:17:46Z",
"severity": "MODERATE"
}