Skip to main content
CISA Known Exploited Vulnerabilities

Apache Flink Improper Access Control Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-05-23
Remediation due
2024-06-13

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/typ0h03zyfrzjqlnb7plh64df1g2383d; https://nvd.nist.gov/vuln/detail/CVE-2020-17519

Description

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Severity

CVSS 3.1 · CISA9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impactpartial

Affected Products

VendorProductAffected versions
Apache Software FoundationApache Flink
Apache Flink 1.11.0 to 1.11.2

References

16 Links
Mailing lists

Record Details

Published
2021-01-05
Last updated
2025-10-21
Assigner (CNA)
apache
Credited to
0rich1 of Ant Security FG Lab

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.