Vulnerabilities (CVE)

Filtered by vendor Linaro Subscribe
Filtered by product Lava
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12563 1 Linaro 1 Lava 2018-08-10 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
CVE-2018-12564 2 Debian, Linaro 2 Debian Linux, Lava 2018-08-10 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.