PT-2022-27412 · Linaro · Lava

Igor Ponomarev

·

Published

2022-11-18

·

Updated

2022-11-23

·

CVE-2022-45132

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linaro Automated Validation Architecture (LAVA) versions prior to 2022.11.1
Description The issue allows remote code execution through user-submitted Jinja2 templates. Specifically, the REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template, which can be exploited to trigger remote code execution in the LAVA server.
Recommendations For versions prior to 2022.11.1, update to version 2022.11.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoint responsible for validating device configuration files in lava-server until the update is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45132

Affected Products

Lava