Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LAVA 代码注入漏洞
Vulnerability Description
LAVA是LAVA开源的一个持续集成系统。用于将操作系统部署到物理和虚拟硬件上以运行测试。 LAVA 2022.11.1之前的版本存在安全漏洞,该漏洞源于其验证设备配置文件的REST API端点将输入加载为Jinja2模板,该模板允许攻击者在LAVA服务器中触发远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A