Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2020-1960
Apache Flink: JMX reporter registry can be rebound by a local attacker
Technology
Apache Flink
CVSS Score
4.7 / 10.0
Affected Versions
Apache Flink 1.1.0 to 1.10.0
Upstream Fix
1.9.3, 1.10.1
Published
May 14, 2020
OSSeva Coverage
Fixed upstream
Description
When a JMX reporter runs with a port set through metrics.reporter.<name>.port, an attacker with local access to the machine and the JMX port can rebind the JMX RMI registry to one they control, compromising JMX connections to the process and the credentials and data sent over them. Removing the port setting mitigates it.
Is your Apache Flink deployment affected?
If you're running Apache Flink 1.1.0 to 1.10.0, you need this patch. Book a discovery call to get covered.