CVE-2022-23848: Critical severity alluxio vulnerability
Published Feb 20, 2022
·Updated
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
Affected Software
1 affected component
Alluxio Alluxio<2.7.3
Event History
Feb 20, 2022
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-23848?
CVE-2022-23848 is considered a medium severity vulnerability due to improper input validation in Alluxio's logserver.
2
How do I fix CVE-2022-23848?
To fix CVE-2022-23848, upgrade Alluxio to version 2.7.3 or later.
3
Which versions of Alluxio are affected by CVE-2022-23848?
CVE-2022-23848 affects Alluxio versions prior to 2.7.3.
4
What impact does CVE-2022-23848 have on my system?
CVE-2022-23848 could allow an attacker to exploit the logserver by sending malicious input, potentially compromising the application.
5
Is CVE-2022-23848 related to the Log4j vulnerability?
No, CVE-2022-23848 is distinct and should not be confused with the CVE-2021-44228 Log4j vulnerability.