CVE-2022-42902: Code Injection
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lavaserver/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lavato a version that resolves this vulnerability.Fixed in 2019.01-5+deb10u2Fixed in 2020.12-5+deb11u2Fixed in 2023.01-2
Event History
Frequently Asked Questions
What is CVE-2022-42902?
CVE-2022-42902 is a vulnerability in Linaro Automated Validation Architecture (LAVA) before 2022.10 that allows an anonymous user to execute user-provided code on the server.
What is the severity of CVE-2022-42902?
CVE-2022-42902 has a severity rating of 8.8 (high).
What software is affected by CVE-2022-42902?
Linaro LAVA versions before 2022.10 and Debian Linux versions 10.0, 11.0 are affected by CVE-2022-42902.
How can I fix CVE-2022-42902?
To fix CVE-2022-42902, update Linaro LAVA to version 2022.10 or later, and update Debian Linux to the recommended versions: 2019.01-5+deb10u2, 2020.12-5+deb11u2, or 2023.01-2.
Where can I find more information about CVE-2022-42902?
You can find more information about CVE-2022-42902 at the following references: [Security Tracker Debian](https://security-tracker.debian.org/tracker/CVE-2022-42902), [Linaro GitLab Merge Request](https://git.lavasoftware.org/lava/lava/-/merge_requests/1834), [Linaro GitLab Commit](https://git.lavasoftware.org/lava/lava/-/commit/e66b74cd6c175ff8826b8f3431740963be228b52?merge_request_iid=1834).