Security Advisory

CVE-2023-38889

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-08-15 00:00:00
Last updated 2024-10-09 13:04:46
Assigner mitre
State PUBLISHED

Description

An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).