Known Vulnerabilities for Lava by Linaro
Listed below are 6 of the newest known vulnerabilities associated with "Lava" by "Linaro".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-28937 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Sear... | Not Provided | 2025-03-11 | 2026-04-23 |
| CVE-2022-45132 json | In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submi... | 9.8 - CRITICAL | 2022-11-18 | 2023-11-07 |
| CVE-2022-44641 json | In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC req... | 6.5 - MEDIUM | 2022-11-18 | 2023-11-07 |
| CVE-2022-42902 json | In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.p... | 8.8 - HIGH | 2022-10-13 | 2023-02-02 |
| CVE-2018-12565 json | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when pa... | 8.8 - HIGH | 2018-06-19 | 2019-09-18 |
| CVE-2018-12564 json | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge ... | 6.5 - MEDIUM | 2018-06-19 | 2018-08-10 |
| CVE-2018-12563 json | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-g... | 6.5 - MEDIUM | 2018-06-19 | 2018-08-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Linaro | Lava | 2018.5 | |||
| Application | Linaro | Lava | 2018.4 | |||
| Application | Linaro | Lava | 2018.2 | |||
| Application | Linaro | Lava | 2018.1 | |||
| Application | Linaro | Lava | 2018.1 | |||
| Application | Linaro | Lava | 2017.9 | |||
| Application | Linaro | Lava | 2017.7 | |||
| Application | Linaro | Lava | 2017.6 | |||
| Application | Linaro | Lava | 2017.5 | |||
| Application | Linaro | Lava | 2017.4 | |||
| Application | Linaro | Lava | 2017.2 | |||
| Application | Linaro | Lava | 2017.12 | |||
| Application | Linaro | Lava | 2017.12 | |||
| Application | Linaro | Lava | 2017.11 | |||
| Application | Linaro | Lava | 2017.11 | |||
| Application | Linaro | Lava | 2017.10 | |||
| Application | Linaro | Lava | 2017.1 | |||
| Application | Linaro | Lava | 2016.9 | |||
| Application | Linaro | Lava | 2016.8 | |||
| Application | Linaro | Lava | 2016.6 |