Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2020-1960

Apache Flink: JMX reporter registry can be rebound by a local attacker

Technology

Apache Flink

CVSS Score

4.7 / 10.0

Affected Versions

Apache Flink 1.1.0 to 1.10.0

Upstream Fix

1.9.3, 1.10.1

Published

May 14, 2020

OSSeva Coverage

Fixed upstream

Description

When a JMX reporter runs with a port set through metrics.reporter.<name>.port, an attacker with local access to the machine and the JMX port can rebind the JMX RMI registry to one they control, compromising JMX connections to the process and the credentials and data sent over them. Removing the port setting mitigates it.

Upstream record: NVD · CVE.org

Is your Apache Flink deployment affected?

If you're running Apache Flink 1.1.0 to 1.10.0, you need this patch. Book a discovery call to get covered.