9.8
CVSSv3

CVE-2022-42468

Published: 26/10/2022 Updated: 28/10/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Apache Flume versions 1.4.0 up to and including 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache flume