VYPR

Maven package

org.alluxio/alluxio-core-common

pkg:maven/org.alluxio/alluxio-core-common

Vulnerabilities (1)

  • CVE-2022-23848CriFeb 20, 2022
    affected < 2.7.3fixed 2.7.3

    In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.