CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
Apache Flink Improper Access Control Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA notes
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/typ0h03zyfrzjqlnb7plh64df1g2383d; https://nvd.nist.gov/vuln/detail/CVE-2020-17519
Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Apache Software Foundation | Apache Flink | Apache Flink 1.11.0 to 1.11.2 |
References
16 Links- [flink-user] 20210105 [CVE-2020-17519] Apache Flink directory traversal attack: reading remote files through the REST API
- [announce] 20210105 [CVE-2020-17519] Apache Flink directory traversal attack: reading remote files through the REST API
- [oss-security] 20210105 [CVE-2020-17519] Apache Flink directory traversal attack: reading remote files through the REST API
- [flink-issues] 20210106 [GitHub] [flink-web] zentol commented on a change in pull request #408: Add security page for Flink
- [flink-issues] 20210110 [jira] [Updated] (FLINK-20916) Typo in test for CVE-2020-17519
- [flink-dev] 20210110 [jira] [Created] (FLINK-20916) Typo in test for CVE-2020-17519
- [flink-issues] 20210110 [jira] [Created] (FLINK-20916) Typo in test for CVE-2020-17519
- [flink-issues] 20210111 [jira] [Assigned] (FLINK-20916) Typo in test for CVE-2020-17519
- [flink-issues] 20210111 [jira] [Commented] (FLINK-20916) Typo in test for CVE-2020-17519
- [flink-dev] 20210113 Re: [DISCUSS] Releasing Apache Flink 1.10.3
- [flink-dev] 20210115 Re: [DISCUSS] Releasing Apache Flink 1.10.3
- [announce] 20210125 Apache Software Foundation Security Report: 2020
- [announce] 20210223 Re: Apache Software Foundation Security Report: 2020
- https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org%3E
- http://packetstormsecurity.com/files/160849/Apache-Flink-1.11.0-Arbitrary-File-Read-Directory-Traversal.html
- https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache.org%3E
Record Details
More from Apache Software Foundation
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Apache Struts Remote Code Execution Vulnerability
mod_proxy SSRF
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.