In Linaro Automated Validation Architecture (LAVA) before...
Critical severity
Unreviewed
Published
Nov 19, 2022
to the GitHub Advisory Database
•
Updated Apr 30, 2025
Description
Published by the National Vulnerability Database
Nov 18, 2022
Published to the GitHub Advisory Database
Nov 19, 2022
Last updated
Apr 30, 2025
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
References