CVE-2022-25167
Estado: ModificadaCrítica (9.8)—
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.08%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20, CWE-74
- NVD-CWE-noinfo
Referencias
- http://www.openwall.com/lists/oss-security/2022/06/14/1
- https://issues.apache.org/jira/browse/FLUME-3416
- https://lists.apache.org/thread/16nf6b81zjpdc4y93ho99oxo83ddbsvg
- http://www.openwall.com/lists/oss-security/2022/06/14/1
- https://issues.apache.org/jira/browse/FLUME-3416
- https://lists.apache.org/thread/16nf6b81zjpdc4y93ho99oxo83ddbsvg
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-25167",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Flume",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "1.4.0",
"status": "affected"
}
],
"version": "flume-jms-source",
"lessThan": "1.10.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-06-14T08:15:06.960",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2022/06/14/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://issues.apache.org/jira/browse/FLUME-3416",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/16nf6b81zjpdc4y93ho99oxo83ddbsvg",
"tags": [
"Broken Link"
],
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2022/06/14/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.apache.org/jira/browse/FLUME-3416",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread/16nf6b81zjpdc4y93ho99oxo83ddbsvg",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-74"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol."
},
{
"lang": "es",
"value": "Apache Flume versiones 1.4.0 hasta 1.9.0, son vulnerables a un ataque de ejecución de código remota (RCE) cuando una configuración usa una fuente JMS con un URI de origen de datos JNDI LDAP cuando un atacante presenta un control del servidor LDAP de destino. Este problema es corregido al limitar JNDI para permitir sólo el uso del protocolo java o ningún protocolo"
}
],
"lastModified": "2026-06-17T04:33:08.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:flume:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BA8104A-9E95-498E-9D2E-30117FE278D5",
"versionEndExcluding": "1.10.0",
"versionStartIncluding": "1.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}