Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2020-6458 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2020-2184 Vulnerability in maven package org.jenkins-ci.plugins:cvs
CVE-2022-36905 Vulnerability in maven package eu.markov.jenkins.plugin.mvnmeta:maven-metadata-plugin
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-main