Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2023-37910 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-api
CVE-2018-16487 Vulnerability in npm package lodash.merge
CVE-2023-32235 Vulnerability in npm package ghost
CVE-2023-46233 Vulnerability in maven package org.webjars.npm:crypto-js
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk15to18