CVE-2020-1960
Command injection in Apache Flink
4.7
MEDIUM
CVSS 3.1
EPSS 0.11%
Description
A vulnerability in Apache Flink where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
How to fix CVE-2020-1960
To remediate CVE-2020-1960, upgrade the affected package to a fixed version below.
- —upgrade to 1.1.6 or later
- —upgrade to 1.9.3 or later
Is CVE-2020-1960 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 1.1.0, < 1.1.6, >= 1.2.0, < 1.2.2, >= 1.3.0, < 1.3.4, >= 1.4.0, < 1.4.3, >= 1.5.0, < 1.5.7, >= 1.6.0, < 1.6.5, >= 1.7.0, < 1.7.3, >= 1.8.0, < 1.8.4, >= 1.9.0, < 1.9.3, >= 1.10.0, < 1.10.1
- from 0, < 1.9.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |