TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2020-17519

HIGHCISA KEV
7.5

Beschreibung

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

CVE Details

CVSS v3.1 Bewertung7.5
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/5/2021
Zuletzt geandert10/27/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerApache
ProduktFlink
SchwachstellennameApache Flink Improper Access Control Vulnerability
KEV Aufnahmedatum2024-05-23
Behebungsfrist2024-06-13
Ransomware-NutzungUnknown

Betroffene Produkte

apache:flink

Schwachen (CWE)

CWE-552CWE-552

Referenzen

http://www.openwall.com/lists/oss-security/2021/01/05/2(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.