GHSA-wx8q-4gm9-rj2g
MODERATECVE-2023-51699OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data.
- Affected
- < 0.9.3
- Fixed in
- 0.9.3
- Weakness
- CWE-78
- Published
- 2024-03-15
- Source
- github