← Back to browse · API

CVE-2022-45132

Severity
CRITICAL
CVSS
9.8
EPSS
0.01859
Risk score
39.85
CISA KEV
No
PoC
No
Published
2022-11-18
Modified
2025-04-30
First seen
2026-08-07
Aliases
EUVD-2022-48049, GHSA-WJXX-HXFJ-HFMH
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-48049

Description

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.

References