logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-45132

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-45132

Description:
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
Last updated date:
11/23/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
11/23/2022
Reference url to background

https://podalirius.net/en/articles/python-vulnerabilities-code-execution-in-jinja-templates/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy