CVE-2020-17519
Path Traversal in Apache Flink
7.5
HIGH
CVSS 3.1
⚠ KEVEPSS 94.3%
Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
How to fix CVE-2020-17519
To remediate CVE-2020-17519, upgrade the affected package to a fixed version below.
- —upgrade to 1.11.3 or later
- —upgrade to 1.11.3 or later
- —upgrade to 1.11.3 or later
Is CVE-2020-17519 being exploited?
Yes — CVE-2020-17519 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (3)
- >= 1.11.0, < 1.11.3
- >= 1.11.0, < 1.11.3
- >= 1.11.0, < 1.11.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H |