CVE-2022-42902
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
- Affected products
- Lava
- Linaro Lava
- < 2022.10
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2022-10-13
CVE-2022-42902 at NVD
1 known exploit for CVE-2022-42902
Proof-of-concept code and exploit modules indexed by Sploitus