Apache Software Foundation Apache Flink vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_flink.
Total CVEs
2
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-17518HIGHCVSS 7.5PoCvApache Flink 1.5.1 to 1.11.22021-01-05
CVE-2020-17518 [HIGH] CWE-23 CVE-2020-17518: Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitra
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was
cvelistv5nvd
CVE-2020-17519HIGHCVSS 7.5KEVPoCvApache Flink 1.11.0 to 1.11.22021-01-05
CVE-2020-17519 [HIGH] CWE-552 CVE-2020-17519: A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attack
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink in
cvelistv5nvd