Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2022-25646 Vulnerability in npm package x-data-spreadsheet
CVE-2018-18950 Vulnerability in maven package org.webjars.bowergithub.kindsoft:kindeditor
CVE-2018-3724 Vulnerability in npm package general-file-server
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2014-1202 Vulnerability in maven package com.smartbear.soapui:soapui-project