[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2018-12564
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

CVE-2018-12565
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.

*OVAL
oval:org.secpod.oval:def:603437
CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/a:linaro:lava-server
cpe:/o:debian:debian_linux:9.x
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies