Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alluxio 代码注入漏洞
Vulnerability Description
Alluxio是Alluxio的提高云中的端到端分布式机器学习速度。 Alluxio 2.9.3 版本及之前版本存在安全漏洞,该漏洞源于通过脚本可以对 lluxio.util.CommonUtils.getUnixGroups(java.lang.String) 的 username 参数执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A