CVE-2023-38889: Alluxio
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
Affected products
- Alluxio Alluxio: up to and including 2.9.3
Published 2023-08-15. Last modified 2026-06-17.