AlluxioCVEs & Vulnerabilities
3 CVEs affecting Alluxio products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
alluxio 3
CVE-2023-38889CRITICAL
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
15 Aug 2023
9.8
CVSS
CVE-2020-21485MEDIUM
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
20 Jun 2023
6.1
CVSS
CVE-2022-23848CRITICAL
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
20 Feb 2022
9.8
CVSS
← PrevPage 1 / 1Next →