Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2017-16222 Vulnerability in npm package elding
CVE-2020-7697 Vulnerability in npm package mock2easy
CVE-2015-1840 Vulnerability in npm package jquery-ujs
CVE-2019-10323 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2022-24891 Vulnerability in maven package org.owasp.esapi:esapi