Sploitus

CVE-2020-17519

25 known exploits for CVE-2020-17519

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Affected products
Apache Flink
Apache Flink
< 1.11.3
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
97.9% (100th percentile)
Weakness
CWE-552
NVD status
Analyzed
Published
2021-01-05
CVE-2020-17519 at NVD
Authoritative description, scoring and affected products

25 known exploits for CVE-2020-17519

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2020-17519
2026-09-13 KitPloitKITPLOIT
CVE-2020-17519
2026-09-13 KitPloitKITPLOIT
apache__flink_CVE-2020-17519_1-11-2
2026-09-13 KitPloitKITPLOIT
CVE-2020-17519
2026-09-13 KitPloitKITPLOIT
SimplesApachePathTraversal
2026-09-13 KitPloitKITPLOIT
CVE-2020-17519
2026-09-12 KitPloitKITPLOIT
CVE-2020-17519
2026-09-12 KitPloitKITPLOIT
CVE-2020-17519
2026-09-09 KitPloitKITPLOIT
CVE-2020-17519-Apache-Flink
2026-09-09 KitPloitKITPLOIT
westone-CVE-2020-17519-scanner
2026-09-09 KitPloitKITPLOIT
CVE-2020-17519-Exp
2026-09-08 KitPloitKITPLOIT
CVE-2020-17519
2026-09-07 KitPloitKITPLOIT
Apache Flink JobManager Traversal
2024-09-01 Brendan Coles, Hoa Nguyen, 0rich1, metasploit.comPACKETSTORMRuby
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-10-15 赵一统GITEE
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-10-13 MrCl0wnLabGITHUB
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-10-05 R3colGITEE
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-01-18 yaunskyGITHUB
Exploit for Path Traversal in Apache Flink
2021-01-10 murataydemirGITHUB
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-01-10 murataydemirGITHUB
Apache Flink 1.11.0 Arbitrary File Read / Directory Traversal
2021-01-08 SunCSRPACKETSTORMRuby
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-01-08 hoanx4GITHUB
Apache Flink Directory Traversal
2021-01-08 Dsquare SecurityD2
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
2021-01-08 SunCSR TeamEXPLOITDBRuby
Exploit for Files or Directories Accessible to External Parties in Apache Flink
2021-01-06 B1anda0GITHUB
Apache Flink JobManager Traversal
2021-01-05 0rich1 - Ant Security FG Lab, Hoa Nguyen - Suncsr Team, bcoles <bcoles@gmail.com>METASPLOITRuby