9.8
CVSSv3

CVE-2022-34916

Published: 21/08/2022 Updated: 11/02/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Flume versions 1.4.0 up to and including 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache flume

Vendor Advisories

Apache Flume versions 140 through 1100 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol ...