CVE-2023-38889

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 15, 2023
Updated: Aug 25, 2023
CWE ID 94

Summary

CVE-2023-38889 is a vulnerability affecting Alluxio version 2.9.3 and earlier. This issue enables an attacker to execute arbitrary code by crafting a malicious script and passing it to the "username" parameter in the function "lluxio.util.CommonUtils.getUnixGroups(java.lang.String)". This vulnerability could potentially lead to serious security consequences if exploited.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share