DEBIAN-CVE-2022-42902

Source
https://security-tracker.debian.org/tracker/CVE-2022-42902
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-42902.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2022-42902
Upstream
Downstream
Published
2022-10-13T03:15:09.057Z
Modified
2026-03-06T05:01:05.139614Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

References

Affected packages

Debian:11 / lava

Package

Name
lava
Purl
pkg:deb/debian/lava?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2020.12-5+deb11u1

Affected versions

2020.*
2020.12-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-42902.json"

Debian:12 / lava

Package

Name
lava
Purl
pkg:deb/debian/lava?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2022.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-42902.json"

Debian:14 / lava

Package

Name
lava
Purl
pkg:deb/debian/lava?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2022.10-1

Affected versions

2018.*
2018.5-1
2018.5-2
2018.5-3~bpo9+1
2018.5-3
2018.5.post1-1
2018.5.post1-2~bpo9+1
2018.5.post1-2
2018.5.post1-3
2018.5.post1-4
2018.10-1
2018.11-1~bpo9+1
2018.11-1
2019.*
2019.01-1
2019.01-2
2019.01-3
2019.01-4
2019.01-5
2019.10-1
2020.*
2020.05-1
2020.06-1
2020.06-2
2020.12-1
2020.12-2
2020.12-3
2020.12-4
2020.12-5
2022.*
2022.01.3-1
2022.01.3-2
2022.01.3-3
2022.01.3-3.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-42902.json"