Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2021-20328 Vulnerability in maven package org.mongodb:mongodb-driver-sync
CVE-2022-41246 Vulnerability in maven package org.jenkins-ci.plugins:ws-execution-manager
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-cdc-mysql-processors