Fedora Account System
Red Hat Associate
Red Hat Customer
Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.
jdg does not ship flume in its delivered code, deptopia references indicate log4j2 for some reason. amq clients points to affected version in maven pom. amq streams does not ship. eap-7 appears to enable flume. eap-xp4 does not ship.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-34916