CVE-2023-38889 is a critical arbitrary code execution vulnerability affecting Alluxio versions 2.9.3 and earlier. An unauthenticated attacker can exploit this flaw remotely by injecting a crafted script into the username parameter of the getUnixGroups function, leading to full compromise of the system. Despite its CVSS score of 9.8, indicating maximum severity and impact, there is currently no public exploit intelligence, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.9.3CPE matchmatch criteria | cpe:2.3:a:alluxio:alluxio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.