Alluxio/alluxio
Releases162
Frequency3 weeks 5 days
Last Release
Stars7.21K
Alluxio, data orchestration for analytics and machine learning in the cloud
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| <= 2.9.3 | 9.8 CRITICAL | — | ||
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String). | ||||
| = 1.8.1 | 6.1 MEDIUM | — | ||
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component. | ||||
| < 2.7.3 | 9.8 CRITICAL | 7.5 HIGH | ||
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability. | ||||