Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45132


In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.


Published

2022-11-18T23:15:29.637

Last Modified

2025-04-30T15:15:58.903

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-94
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linaro lava < 2022.11.1 Yes

References