Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2020-10686 Vulnerability in maven package org.keycloak:keycloak-model-jpa
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk15to18
CVE-2020-12480 Vulnerability in maven package com.typesafe.play:play_2.12
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-vertx-http
CVE-2020-10203 Vulnerability in maven package org.sonatype.nexus:nexus-core