CVE-2023-38889: Alluxio

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).

Affected products

  • Alluxio Alluxio: up to and including 2.9.3

Published 2023-08-15. Last modified 2026-06-17.