Apache Flink vulnerabilities

3 known vulnerabilities affecting apache/flink.

Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2020-17518HIGHCVSS 7.5PoC≥ 1.5.1, < 1.11.32021-01-05
CVE-2020-17518 [HIGH] CWE-23 CVE-2020-17518: Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitra Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was
nvd
CVE-2020-17519HIGHCVSS 7.5KEVPoC≥ 1.11.0, < 1.11.32021-01-05
CVE-2020-17519 [HIGH] CWE-552 CVE-2020-17519: A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attack A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink in
nvd
CVE-2020-1960MEDIUMCVSS 4.7≥ 1.1.0, ≤ 1.1.5≥ 1.2.0, ≤ 1.2.1+8 more2020-05-14
CVE-2020-1960 [MEDIUM] CVE-2020-1960: A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5 A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX
nvd