CVE-2020-17519

Confirmed PUBLISHED

Apache Flink directory traversal attack: reading remote files through the REST API

Apache Software Foundation · Apache Flink
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High EPSS 97.9%

At a Glance

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

cisa apache nessus_scanner nuclei_scanner
CVE Published
Jan 05, 2021
Exploitation Reported
May 23, 2024
CVSS
7.5 High
EPSS
97.9%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
apache
flink

1.11.0 to <= 1.11.2

Affected
Apache Software Foundation
Apache Flink

Apache Flink 1.11.0 to 1.11.2

Affected

CVE References

Show 11 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.