CVE-2020-17519
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
- Affected products
- Apache Flink
- Apache Flink
- < 1.11.3
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 97.9% (100th percentile)
- Weakness
- CWE-552
- NVD status
- Analyzed
- Published
- 2021-01-05
CVE-2020-17519 at NVD
25 known exploits for CVE-2020-17519
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-17519
CVE-2020-17519
apache__flink_CVE-2020-17519_1-11-2
CVE-2020-17519
SimplesApachePathTraversal
CVE-2020-17519
CVE-2020-17519
CVE-2020-17519
CVE-2020-17519-Apache-Flink
westone-CVE-2020-17519-scanner
CVE-2020-17519-Exp
CVE-2020-17519
Apache Flink JobManager Traversal
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Exploit for Path Traversal in Apache Flink
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Apache Flink 1.11.0 Arbitrary File Read / Directory Traversal
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Apache Flink Directory Traversal
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
Exploit for Files or Directories Accessible to External Parties in Apache Flink
Apache Flink JobManager Traversal