Your submission was sent successfully! Close

CVE-2018-12564

Published: 19 June 2018

An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
lava
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

precise Does not exist

trusty Does not exist

upstream
Released (2018.5.post1-1)
xenial Does not exist

lava-server
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

precise Does not exist

trusty Does not exist

upstream Needs triage

xenial Does not exist