Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-17518

Apache Flink: REST handler writes uploaded files to any location

Technology

Apache Flink

CVSS Score

7.5 / 10.0

Affected Versions

Apache Flink 1.5.1 to 1.11.2

Upstream Fix

1.11.3, 1.12.0

Published

January 5, 2021

OSSeva Coverage

Fixed upstream

Description

A REST handler introduced in Flink 1.5.1 lets a maliciously modified HTTP header write an uploaded file to any location on the local filesystem that the Flink process can write to.

Upstream record: NVD · CVE.org

Is your Apache Flink deployment affected?

If you're running Apache Flink 1.5.1 to 1.11.2, you need this patch. Book a discovery call to get covered.