Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LAVA 安全漏洞
Vulnerability Description
LAVA是LAVA开源的一个持续集成系统。用于将操作系统部署到物理和虚拟硬件上以运行测试。 LAVA 2022.10之前版本存在安全漏洞,该漏洞源于输入清理不当,在lava_server/lavatable.py中有动态代码执行,匿名用户可以强制lava-server-gunicorn服务在服务器上执行用户提供的代码。
CVSS Information
N/A
Vulnerability Type
N/A