Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2022-25312 Vulnerability in maven package org.apache.any23:apache-any23
CVE-2019-10423 Vulnerability in maven package com.villagechief.codescan.jenkins:codescan
CVE-2023-32071 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2020-2138 Vulnerability in maven package org.jenkins-ci.plugins:cobertura
CVE-2021-46364 Vulnerability in maven package info.magnolia:magnolia-core