Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2019-12423 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-jose
CVE-2023-31065 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2021-21349 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-coyote