Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-59202
HistoryAug 24, 2022 - 12:00 a.m.

Apache Flume input validation error vulnerability

2022-08-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
19
apache flume
input validation
rce
ldap
jms source
jndi ldap

EPSS

0.003

Percentile

69.6%

Apache Flume is a distributed, reliable and available service from the Apache Foundation, USA. Used to efficiently collect, aggregate, and move large amounts of log data, versions of Apache Flume prior to 1.4.0 through 1.10.0 contain a security vulnerability that stems from vulnerability to remote code execution (RCE) attacks when an attacker controls the configuration of an LDAP server using a JMS Source with a JNDI LDAP data source URI. No detailed vulnerability details are currently available.

EPSS

0.003

Percentile

69.6%