Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Remediation
References
https://github.com/Alluxio/alluxio/issues/17766
Related Vulnerabilities
CVE-2023-31999 Vulnerability in npm package @fastify/oauth2
CVE-2019-20149 Vulnerability in maven package org.webjars.npm:kind-of
CVE-2016-10541 Vulnerability in maven package org.webjars.npm:shell-quote
CVE-2022-41713 Vulnerability in npm package deep-object-diff
CVE-2023-32070 Vulnerability in maven package org.xwiki.platform:xwiki-core-rendering-api