Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    3
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-79787

    Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2023-38889

    An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).

    Last Modified: Nov 21, 2024
    Published: Aug 15, 2023

    CVE-2020-21485

    Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.

    Last Modified: Dec 09, 2024
    Published: Jun 20, 2023

    CVE-2022-23848

    In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

    Last Modified: Nov 21, 2024
    Published: Feb 20, 2022
    Items Per Page
    Alluxio Vulnerabilities & Security CVEs | CVE-DB