Vulnerability Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Flink | >= 1.11.0, < 1.11.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160849/Apache-Flink-1.11.0-Arbitrary-File-RExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2021/01/05/2Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r0a433be10676f4fe97ca423d08f914e0ead341c901Mailing List
- https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a9Mailing List
- https://lists.apache.org/thread.html/r229167538863518738e02f4c1c5a8bb34c1d45dadcIssue Tracking
- https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93Issue Tracking
- https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623Issue Tracking
- https://lists.apache.org/thread.html/r2fc60b30557e4a537c2a6293023049bd1c49fd92b5Issue Tracking
- https://lists.apache.org/thread.html/r4e1b72bfa789ea5bc20b8afe56119200ed25bdab0eMailing ListVendor Advisory
- https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038Issue Tracking
- https://lists.apache.org/thread.html/r88b55f3ebf1f8f4e1cc61f030252aaef4b77060b56Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/r88f427865fb6aa6e6378efe07632a1906b430365e1Mailing ListVendor Advisory
FAQ
What is CVE-2020-17519?
CVE-2020-17519 is a vulnerability with a CVSS score of 7.5 (HIGH). A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the Job...
How severe is CVE-2020-17519?
CVE-2020-17519 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-17519?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Flink.