Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2023-38509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2018-12542 Vulnerability in maven package io.vertx:vertx-web
CVE-2018-5673 Vulnerability in maven package org.dojotoolkit:dojo
CVE-2023-35931 Vulnerability in npm package shescape
CVE-2021-25864 Vulnerability in npm package node-red-contrib-huemagic