CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
Configurations

Configuration 1

cpe:2.3:a:apache:flume:*:*:*:*:*:*:*:*

Information

Published : 2022-10-26 04:15

Updated : 2022-10-28 05:41


NVD link : CVE-2022-42468

Mitre link : CVE-2022-42468

Products Affected
No products.