Vulnerabilities > CVE-2022-23848 - Unspecified vulnerability in Alluxio

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
alluxio

Summary

In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

Vulnerable Configurations

Part Description Count
Application
Alluxio
1