TROYANOSYVIRUS
Volver a CVEs

CVE-2020-17519

HIGHCISA KEV
7.5

Descripcion

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Detalles CVE

Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/5/2021
Ultima modificacion10/27/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorApache
ProductoFlink
Nombre vulnerabilidadApache Flink Improper Access Control Vulnerability
Fecha inclusion KEV2024-05-23
Fecha limite remediacion2024-06-13
Uso en ransomwareUnknown

Productos afectados

apache:flink

Debilidades (CWE)

CWE-552CWE-552

Referencias

http://www.openwall.com/lists/oss-security/2021/01/05/2(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.