Junglewise Threat Intelligence

CVE-2022-42468: Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL

CVE-2022-42468 · Severity: low · CVSS 3.1 · Published 2022-10-26

Technologies: org.apache.flume.flume-ng-sources:flume-jms-source (Maven). Vendors: Maven.

Executive brief

Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL

Affected products

  • Maven org.apache.flume.flume-ng-sources:flume-jms-source

Related threats