Description
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Remediation
References
https://www.alluxio.io/download/releases/alluxio-2-7-3-release/
Related Vulnerabilities
CVE-2018-17960 Vulnerability in maven package org.webjars.npm:ckeditor
CVE-2019-13127 Vulnerability in npm package mxgraph
CVE-2020-13941 Vulnerability in maven package org.apache.solr:solr-core
CVE-2023-46131 Vulnerability in maven package org.grails:grails-web-common
CVE-2023-34659 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent