Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2022-34192 Vulnerability in maven package org.jenkins-ci.plugins:ontrack
CVE-2017-1000090 Vulnerability in maven package org.jenkins-ci.plugins:role-strategy
CVE-2023-27479 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui
CVE-2020-2239 Vulnerability in maven package org.jenkins-ci.plugins:parameterized-remote-trigger
CVE-2019-1003081 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer