Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-17519

Apache Flink: JobManager REST API reads any local file

Technology

Apache Flink

CVSS Score

7.5 / 10.0

Affected Versions

Apache Flink 1.11.0 to 1.11.2

Upstream Fix

1.11.3, 1.12.0

Published

January 5, 2021

OSSeva Coverage

Fixed upstream

Description

A change introduced in Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem that the JobManager process can access, through its REST interface. CISA added it to the Known Exploited Vulnerabilities catalogue on 23 May 2024.

Upstream record: NVD · CVE.org

Is your Apache Flink deployment affected?

If you're running Apache Flink 1.11.0 to 1.11.2, you need this patch. Book a discovery call to get covered.