Apache Flink vulnerabilities
4 known vulnerabilities affecting apache/flink.
Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-17519P1HIGHCVSS 7.5KEVPoC≥ 1.11.0, < 1.11.32021-01-05
CVE-2020-17519 [HIGH] CWE-552 CVE-2020-17519: A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attack
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink in
nvd
CVE-2020-17518P1HIGHCVSS 7.5ExploitedPoC≥ 1.5.1, < 1.11.32021-01-05
CVE-2020-17518 [HIGH] CWE-23 CVE-2020-17518: Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitra
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was
nvd
CVE-2026-35194P3HIGHCVSS 8.1≥ 1.15.0, < 1.20.4≥ 2.0.0, < 2.0.2+2 more2026-05-15
CVE-2026-35194 [HIGH] CWE-94 CVE-2026-35194: Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x al
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlle
nvd
CVE-2020-1960P4MEDIUMCVSS 4.7≥ 1.1.0, ≤ 1.1.5≥ 1.2.0, ≤ 1.2.1+8 more2020-05-14
CVE-2020-1960 [MEDIUM] CVE-2020-1960: A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX
nvd