CVE-2018-12563
NONE EPSS 54.8%
Published Jun 19, 20188y ago · Modified Jun 17, 20262w ago
Published Jun 19, 2018 8y ago
Last Modified Jun 17, 2026 2w ago
Description
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
Threat Intelligence
EPSS Exploit Probability
54.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-20 Improper Input Validation Validation
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| linaro | lava | * | <2018.5.post1 |
References 1
- git.linaro.org https://git.linaro.org/lava/lava.git/commit/?id=e24ec39599bc07562ad8bc2a581144b8448cb214
Remediation
- git.linaro.org https://git.linaro.org/lava/lava.git/commit/?id=e24ec39599bc07562ad8bc2a581144b8448cb214