CVE Database
/

CVE-2022-34916

Back to search

CVE-2022-34916

Published: Aug 21, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

VendorProductVersions

Apache Software Foundation

Apache Flume

affected
flume-jms-source - < 1.11.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now