CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
code execution
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2022-42902
Severity
HIGH
CVSS
8.8
EPSS
1.31%
Original NVD Description
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.