Severity, medium

Description:

Flumeā€™s JMSSource class can be configured with a providerUrl parameter. A JNDI 
lookup is performed on this name without performing an validation. This could 
result in untrusted data being deserialized.

Mitigation
Upgrade to Flume 1.11.0.

In releases 1.4.0 through 1.10.1 the JMSSource should not be used.

Release Details
In release 1.11.0, if a protocol is specified in the connection factory 
parameter only the java protocol will be allowed. If no protocol is specified 
it will also be allowed.

Credit
This issue was found by nbxiglk.

Reply via email to