CVE-2020-21485: XSS
Published Jun 20, 2023
·Updated
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
Affected Software
2 affected components
maven/org.alluxio:alluxio-parent<=1.8.1
Alluxio Alluxio=1.8.1
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-21485?
CVE-2020-21485 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2020-21485?
To fix CVE-2020-21485, upgrade Alluxio to version 2.0.0 or later, where the vulnerability has been patched.
3
Which versions are affected by CVE-2020-21485?
CVE-2020-21485 affects Alluxio versions up to and including 1.8.1.
4
What type of vulnerability is CVE-2020-21485?
CVE-2020-21485 is a Cross Site Scripting (XSS) vulnerability.
5
Can CVE-2020-21485 lead to data breaches?
Yes, CVE-2020-21485 can potentially allow attackers to execute arbitrary code, leading to data breaches.