CVE-2018-12564 — Improper Input Validation in Lava
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 45.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 19
Latest updateMay 14
Description
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 8.0, 9.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2018-12564: lava - An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support f...↗2018