CVE-2022-42468
Estado: ModificadaCrítica (9.8)—
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.99%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20, CWE-74
Referencias
- https://issues.apache.org/jira/browse/FLUME-3437
- https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvz
- https://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78
- https://issues.apache.org/jira/browse/FLUME-3437
- https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvz
- https://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-42468",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-42468",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-07T13:52:39.109692Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache Flume",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "1.4.0",
"status": "affected"
}
],
"version": "Flume JMSSource",
"lessThan": "1.11.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-10-26T16:15:11.823",
"references": [
{
"url": "https://issues.apache.org/jira/browse/FLUME-3437",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvz",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "security@apache.org"
},
{
"url": "https://issues.apache.org/jira/browse/FLUME-3437",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread/1ckhmp539zr2nd2rs45pocpywk2d9zvz",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.apache.org/thread/939wkx8o90bp6m2ht3t1sdyo1ncypl78",
"tags": [
"Mailing List",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-74"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol."
},
{
"lang": "es",
"value": "Apache Flume versiones 1.4.0 hasta 1.10.1, son vulnerables a un ataque de ejecución de código remota (RCE) cuando una configuración usa una fuente JMS con una providerURL no segura. Este problema es corregido al limitar JNDI para permitir sólo el uso del protocolo java o ningún protocolo"
}
],
"lastModified": "2026-06-17T05:04:58.770",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:flume:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36C2D3C9-225E-403F-B154-9372AB11A0F7",
"versionEndIncluding": "1.10.1",
"versionStartIncluding": "1.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@apache.org"
}