Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-42902

Опубликовано: 13 окт. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 8.8

Описание

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

2023.01-2
esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

DNE

lunar

not-affected

2023.01-2
trusty

ignored

end of standard support
upstream

released

2022.10-1
xenial

ignored

end of standard support

Показывать по

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

CVSS3: 8.8
debian
больше 3 лет назад

In Linaro Automated Validation Architecture (LAVA) before 2022.10, the ...

CVSS3: 8.8
github
больше 3 лет назад

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

8.8 High

CVSS3