CVE-2018-12563

NONE EPSS 54.8%
Published Jun 19, 20188y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jun 19, 2018 8y ago
Last Modified Jun 17, 2026 2w ago

Description

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.

Threat Intelligence

EPSS Exploit Probability
54.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-20 Improper Input Validation Validation

Affected Products 1

VendorProductVersionRange
linarolava* <2018.5.post1

References 1

  • git.linaro.org https://git.linaro.org/lava/lava.git/commit/?id=e24ec39599bc07562ad8bc2a581144b8448cb214
    PatchThird Party Advisory

Remediation

  • git.linaro.org https://git.linaro.org/lava/lava.git/commit/?id=e24ec39599bc07562ad8bc2a581144b8448cb214
    PatchThird Party Advisory