CVE-2022-45132: Code Injection
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lavato a version that resolves this vulnerability.Fixed in 2019.01-5Fixed in 2019.01-5+deb10u2Fixed in 2020.12-5+deb11u2Fixed in 2023.01-2 - Upgrade
Upgrade
Linaro LAVA (lava-server)to a version that resolves this vulnerability.Fixed in 2022.11.1 - Compensating control
Restrict the lava-server REST API endpoint used for validating device configuration files to trusted users/systems until the upgrade to 2022.11.1 is applied.
Event History
Frequently Asked Questions
What is CVE-2022-45132?
CVE-2022-45132 is a vulnerability in Linaro Automated Validation Architecture (LAVA) that allows remote code execution through a user-submitted Jinja2 template.
How can CVE-2022-45132 be exploited?
CVE-2022-45132 can be exploited by submitting a malicious Jinja2 template through the REST API endpoint for validating device configuration files in LAVA.
What is the severity of CVE-2022-45132?
CVE-2022-45132 has a severity rating of 9.8 (Critical).
What software versions are affected by CVE-2022-45132?
Linaro LAVA versions before 2022.11.1 and Debian package versions 2019.01-5, 2019.01-5+deb10u2, 2020.12-5+deb11u2, and 2023.01-2 are affected by CVE-2022-45132.
How can I fix CVE-2022-45132?
To fix CVE-2022-45132, update Linaro LAVA to version 2022.11.1 or later, and Debian package lava to the recommended versions: 2019.01-5, 2019.01-5+deb10u2, 2020.12-5+deb11u2, or 2023.01-2.