In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
2022-11-18T23:15:29.637
2025-04-30T15:15:58.903
Modified
CVSSv3.1: 9.8 (CRITICAL)