CVE-2020-1960
published 2020-05-14CVE-2020-1960: A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to…
PriorityP425medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.86%
54.3th percentile
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | flink | — | — |
| apache | flink | — | — |
| apache | flink | 1.1.0 – 1.1.5 | — |
| apache | flink | 1.2.0 – 1.2.1 | — |
| apache | flink | 1.3.0 – 1.3.3 | — |
| apache | flink | 1.4.0 – 1.4.2 | — |
| apache | flink | 1.5.0 – 1.5.6 | — |
| apache | flink | 1.6.0 – 1.6.4 | — |
| apache | flink | 1.7.0 – 1.7.2 | — |
| apache | flink | 1.8.0 – 1.8.3 | — |
| apache | flink | 1.9.0 – 1.9.2 | — |
| juniper | junos_os | — | — |
| juniper | mx_series | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_apache4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
apache-flink: JMX information disclosure vulnerability
vendor_redhat·2020-05-13·CVSS 4.7
CVE-2020-1960 [MEDIUM] CWE-20 apache-flink: JMX information disclosure vulnerability
apache-flink: JMX information disclosure vulnerability
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Apache
Apache flink: CVE-2020-1960
vendor_apache·CVSS 4.7
CVE-2020-1960 [MEDIUM] Apache flink: CVE-2020-1960
Apache flink: CVE-2020-1960
1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0 Users are advised to upgrade to Flink 1.9.3 or 1.10.1 or later versions or remove the port parameter from the reporter configuration (see advisory for details).
OSV
Command injection in Apache Flink
osv·2021-05-21
CVE-2020-1960 [MEDIUM] Command injection in Apache Flink
Command injection in Apache Flink
A vulnerability in Apache Flink where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
GHSA
Command injection in Apache Flink
ghsa·2021-05-21
CVE-2020-1960 [MEDIUM] CWE-74 Command injection in Apache Flink
Command injection in Apache Flink
A vulnerability in Apache Flink where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
bugzilla·2020-09-03·CVSS 5.4
CVE-2020-2231 [MEDIUM] CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
CVE-2020-2231 jenkins: stored XSS vulnerability in 'trigger builds remotely'
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely'. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Discussion:
External References:
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1960
---
Created jenkins tracking bugs for this issue:
Affects: fedora-31 [bug 1875235]
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.5
Via RHSA-2020:3841 https://access.redhat.com/errata/RHSA-2020:3841
---
This bug is now closed. Further updates for individua
Bugzilla
CVE-2020-1960 apache-flink: JMX information disclosure vulnerability
bugzilla·2020-06-17·CVSS 4.7
CVE-2020-1960 [MEDIUM] CVE-2020-1960 apache-flink: JMX information disclosure vulnerability
CVE-2020-1960 apache-flink: JMX information disclosure vulnerability
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Reference:
https://lists.apache.org/thread.html/r23e559dee1e69741557b5fe431846de1f1a598
https://lists.apache.org/thread.html/r23e559dee1e69741557b5fe431846de1f1a5981356d0ddb9482df88a%40%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r663cf0d5c386bba2f562d45ad484d786151a84f0b95e45e2b0fb8e50%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r23e559dee1e69741557b5fe431846de1f1a5981356d0ddb9482df88a%40%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r663cf0d5c386bba2f562d45ad484d786151a84f0b95e45e2b0fb8e50%40%3Cissues.flink.apache.org%3E
2020-05-14
Published