Critical severity9.8NVD Advisory· Published Oct 26, 2022· Updated Jun 17, 2026
CVE-2022-42468
CVE-2022-42468
Description
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.flume.flume-ng-sources:flume-jms-sourceMaven | < 1.11.0 | 1.11.0 |
Affected products
3- Apache Software Foundation/Apache Flumev5Range: Flume JMSSource
Patches
Vulnerability mechanics
References
6- lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78nvdMailing ListPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-9w4g-fp9h-3q2vghsaADVISORY
- issues.apache.org/jira/browse/FLUME-3437nvdIssue TrackingVendor AdvisoryWEB
- lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvznvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42468ghsaADVISORY
- github.com/apache/flume/commit/eee179a09df405c1ab55ae25a53b76ca1050bb97ghsaWEB
News mentions
0No linked articles in our index yet.