#VU71186 Code Injection in Linaro Automated Validation Architecture (LAVA) - CVE-2022-45132
Published: January 16, 2023
Linaro Automated Validation Architecture (LAVA)
Linaro Limited
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when handling Jinja2 templates. A remote user can submit a specially crafted Jinja2 template to the REST API endpoint for validating device configuration files in lava-server and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.