Vulnerabilities
Vulnerable Software
Linaro:  >> Lava  >> 2022.11  Security Vulnerabilities
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
CVSS Score
9.8
EPSS Score
0.05
Published
2022-11-18


Contact Us

Shodan ® - All rights reserved