CVE-2023-51699

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
15/03/2024
Last modified:
09/04/2025

Description

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to create or update the K8s CRD Dataset/JuicefsRuntime, to execute arbitrary OS commands within the juicefs related containers. This could lead to unauthorized access, modification or deletion of data. Users who're using versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:fluid:*:*:*:*:*:*:*:* 0.9.3 (excluding)