← Back to CVE List

CVE-2022-42468

Published: 2022-10-26T16:15Z
Last Modified: 2024-11-21T07:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt