fig. 01 — GHSA-xrrh-h86w-pwfj, the advisory selected below
// advisories
GHSA-xrrh-h86w-pwfj
CRITICALCVE-2023-38889
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).