CVE-2022-42468
published 2022-10-26CVE-2022-42468: Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.72%
84.5th percentile
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | flume | 1.4.0 – 1.10.1 | — |
| apache_software_foundation | apache_flume | >= Flume JMSSource < 1.11.0 | 1.11.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
ghsa·2022-10-26
CVE-2022-42468 [CRITICAL] CWE-20 Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Flume’s JMSSource class can be configured with a providerUrl parameter. A JNDI lookup is performed on this name without performing validation. This could result in untrusted data being deserialized, leading to remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed in version 1.11.0.
OSV
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
osv·2022-10-26
CVE-2022-42468 [CRITICAL] Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Flume’s JMSSource class can be configured with a providerUrl parameter. A JNDI lookup is performed on this name without performing validation. This could result in untrusted data being deserialized, leading to remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed in version 1.11.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.apache.org/jira/browse/FLUME-3437https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvzhttps://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78https://issues.apache.org/jira/browse/FLUME-3437https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvzhttps://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78
2022-10-26
Published