VYPR
High severity8.8NVD Advisory· Published Oct 13, 2022· Updated Jun 17, 2026

CVE-2022-42902

CVE-2022-42902

Description

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

Affected products

5
  • Linaro/Lava2 versions
    cpe:2.3:a:linaro:lava:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:linaro:lava:*:*:*:*:*:*:*:*range: <2022.10
    • (no CPE)range: <2022.10
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Linaro/Automated Validation Architecturedescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.