An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
| Software | From | Fixed in |
|---|---|---|
| linaro / lava | - | 2018.4.x |
| debian / debian_linux | 9.0 | 9.0.x |