TROYANOSYVIRUS
Voltar para CVEs

CVE-2020-17519

HIGHCISA KEV
7.5

Descricao

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Detalhes CVE

Pontuacao CVSS v3.17.5
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/5/2021
Ultima modificacao10/27/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorApache
ProdutoFlink
Nome da vulnerabilidadeApache Flink Improper Access Control Vulnerability
Data inclusao KEV2024-05-23
Prazo de remediacao2024-06-13
Uso em ransomwareUnknown

Produtos afetados

apache:flink

Fraquezas (CWE)

CWE-552CWE-552

Referencias

http://www.openwall.com/lists/oss-security/2021/01/05/2(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.