CVE-2022-42902

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/10/2022
Last modified:
15/05/2025

Description

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linaro:lava:*:*:*:*:*:*:*:* 2022.10 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*