Linaro Lava vulnerabilities

6 known vulnerabilities affecting linaro/lava.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2022-45132CRITICALCVSS 9.8fixed in 2022.11.12022-11-18
CVE-2022-45132 [CRITICAL] CWE-94 CVE-2022-45132: In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be ac In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
nvdosv
CVE-2022-44641MEDIUMCVSS 6.5fixed in 2022.112022-11-18
CVE-2022-44641 [MEDIUM] CWE-776 CVE-2022-44641: In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
nvdosv
CVE-2022-42902HIGHCVSS 8.8fixed in 2022.102022-10-13
CVE-2022-42902 [HIGH] CWE-94 CVE-2022-42902: In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution i In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
nvdosv
CVE-2018-12565HIGHCVSS 8.8≤ 2018.42018-06-19
CVE-2018-12565 [HIGH] CWE-20 CVE-2018-12565: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
nvdosv
CVE-2018-12564MEDIUMCVSS 6.5fixed in 2018.5.post12018-06-19
CVE-2018-12564 [MEDIUM] CWE-20 CVE-2018-12564: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submi An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.
nvdosv
CVE-2018-12563MEDIUMCVSS 6.5fixed in 2018.5.post12018-06-19
CVE-2018-12563 [MEDIUM] CWE-20 CVE-2018-12563: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a use An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
nvdosv