Known Vulnerabilities for Alluxio by Alluxio
Listed below are 3 of the newest known vulnerabilities associated with "Alluxio" by "Alluxio".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-79787 json | Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthentic... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2023-38889 json | An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username para... | 9.8 - CRITICAL | 2023-08-15 | 2023-08-25 |
| CVE-2022-23848 json | In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 L... | 9.8 - CRITICAL | 2022-02-20 | 2022-02-28 |
| CVE-2020-21485 json | Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parame... | 6.1 - MEDIUM | 2023-06-20 | 2023-06-27 |