Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2022-33682 Vulnerability in maven package org.apache.pulsar:pulsar-proxy
CVE-2020-36640 Vulnerability in maven package org.bonitasoft.connectors:bonita-connector-webservice
CVE-2018-1000152 Vulnerability in maven package org.jenkins-ci.plugins:vsphere-cloud
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2023-24459 Vulnerability in maven package org.jenkins-ci.plugins:bearychat