9.8
CVSSv3

CVE-2022-23848

Published: 20/02/2022 Updated: 28/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Alluxio prior to 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alluxio alluxio

Github Repositories

My security advisories

My latest public security advisories CVE-2022-21404: Applications using Oracle Helidon versions 09x, 010x, 011x, 10x, 11x, 12x, 13x, 14x, 200-M1, 200-M2, 200-M3, 200-M4 and 200-RC1 are affected by a remote code execution vulnerability caused by insecure YAML deserialization when using the class UrlConfigSource for loading configuration files remotely