Lava
Linaro · 6 CVEs
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user…
Nov 18, 2022
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLR…
Nov 18, 2022
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavat…
Oct 13, 2022
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() w…
Jun 19, 2018
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can…
Jun 19, 2018
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-se…
Jun 19, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-45132 | In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API… | CRITICAL | 2.01% | Nov 18, 2022 |
| CVE-2022-44641 | In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML e… | MEDIUM | 1.05% | Nov 18, 2022 |
| CVE-2022-42902 | In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitizat… | HIGH | 1.37% | Oct 13, 2022 |
| CVE-2018-12565 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execu… | HIGH | 2.47% | Jun 19, 2018 |
| CVE-2018-12564 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force la… | MEDIUM | 1.50% | Jun 19, 2018 |
| CVE-2018-12563 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from… | MEDIUM | 0.89% | Jun 19, 2018 |
Showing 1 to 6 of 6 CVEs