Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhr6-gv2v-7888

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

EPSS

Процентиль: 54%
0.00308
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of ...

EPSS

Процентиль: 54%
0.00308
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20