AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-34916

CRITICAL · CVSS 9.8 EPSS 2.36% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-08-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-34916
Severity
CRITICAL
CVSS
9.8
EPSS
2.36%
Apache Java

Original NVD Description

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.