CVE-2018-12563: Input Validation
Published Jun 19, 2018
·Updated
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
Affected Software
1 affected component
Linaro LAVA<2018.5.post1
Remediation
Event History
Jun 19, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-12563.
2
What is the severity level of CVE-2018-12563?
The severity level of CVE-2018-12563 is medium, with a severity value of 6.5.
3
What is the affected software by CVE-2018-12563?
The affected software by CVE-2018-12563 is Linaro LAVA before version 2018.5.post1.
4
How can an attacker exploit CVE-2018-12563?
An attacker can exploit CVE-2018-12563 by using a file: URL to force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
5
Is there a fix available for CVE-2018-12563?
Yes, a fix is available for CVE-2018-12563. Please refer to the Linaro LAVA Git commit for more information.