Sploitus

CVE-2022-42902

1 known exploit for CVE-2022-42902

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

Affected products
Lava
Linaro Lava
< 2022.10
CVSS 3.1
8.8 HIGH
EPSS
1.3% (68th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2022-10-13
CVE-2022-42902 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-42902

Proof-of-concept code and exploit modules indexed by Sploitus