Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2023-26108 Vulnerability in npm package @nestjs/core
CVE-2018-14041 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2023-36477 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2021-23771 Vulnerability in npm package notevil
CVE-2023-34602 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core