Export limit exceeded: 382628 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79787 | 1 Alluxio | 1 Alluxio | 2026-08-25 | 9.8 Critical |
| Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data. | ||||
| CVE-2020-21485 | 1 Alluxio | 1 Alluxio | 2024-12-09 | 6.1 Medium |
| Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component. | ||||
| CVE-2023-38889 | 1 Alluxio | 1 Alluxio | 2024-11-21 | 9.8 Critical |
| An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String). | ||||
| CVE-2022-23848 | 1 Alluxio | 1 Alluxio | 2024-11-21 | 9.8 Critical |
| In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability. | ||||
Page 1 of 1.