CVE Database
/

CVE-2022-42468

Back to search

CVE-2022-42468

Published: Oct 26, 2022

Modified: May 7, 2025

PUBLISHED

Description

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

VendorProductVersions

Apache Software Foundation

Apache Flume

affected
Flume JMSSource - < 1.11.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now