Alluxio provides a distributed storage abstraction layer and data-orchestration platform deployed in cloud and big-data environments, with its vulnerability footprint concentrated in a single product line. The durable signal centers on input-handling and code-generation weaknesses, including code injection, cross-site scripting, and related input-validation gaps characteristic of web-facing services and dynamic code paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alluxio over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38889CRITICAL An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lan | Aug 15, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-23848CRITICAL In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability. | Feb 20, 2022 | 9.8 | 24 | NO | NO |
CVE-2020-21485MEDIUM Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component. | Jun 20, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alluxio.
Media articles that mention a CVE ID that affects a product developed by Alluxio — matched by CVE ID, not by vendor name.