Vulnerabilities > Alluxio > Alluxio > 2.4.0.rc3

DATE CVE VULNERABILITY TITLE RISK
2023-08-15 CVE-2023-38889 Code Injection vulnerability in Alluxio
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
network
low complexity
alluxio CWE-94
critical
9.8
2022-02-20 CVE-2022-23848 Unspecified vulnerability in Alluxio
In Alluxio before 2.7.3, the logserver does not validate the input stream.
network
low complexity
alluxio
critical
9.8