DEBIAN-CVE-2022-45132

Source
https://security-tracker.debian.org/tracker/CVE-2022-45132
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-45132.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2022-45132
Upstream
Published
2022-11-18T23:15:29Z
Modified
2026-09-01T20:04:49Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.

References

Affected packages

Debian:12 / lava

Package

Name
lava
Purl
pkg:deb/debian/lava?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2023.01-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-45132.json"

Debian:14 / lava

Package

Name
lava
Purl
pkg:deb/debian/lava?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2023.01-1

Affected versions

2018.*
2018.5-1
2018.5-2
2018.5-3~bpo9+1
2018.5-3
2018.5.post1-1
2018.5.post1-2~bpo9+1
2018.5.post1-2
2018.5.post1-3
2018.5.post1-4
2018.10-1
2018.11-1~bpo9+1
2018.11-1
2019.*
2019.01-1
2019.01-2
2019.01-3
2019.01-4
2019.01-5
2019.10-1
2020.*
2020.05-1
2020.06-1
2020.06-2
2020.12-1
2020.12-2
2020.12-3
2020.12-4
2020.12-5
2022.*
2022.01.3-1
2022.01.3-2
2022.01.3-3
2022.01.3-3.1
2022.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-45132.json"