PT-2021-10096 · Apache · Apache Flink
0Rich1
+1
·
Published
2021-01-05
·
Updated
2024-03-06
·
CVE-2020-17518
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Flink versions 1.5.1
Description:
A REST handler in Apache Flink allows writing an uploaded file to any location on the local file system through a maliciously modified HTTP HEADER. This issue enables files to be written to any location accessible by the software.
Recommendations:
For Apache Flink version 1.5.1, upgrade to Flink 1.11.3 or 1.12.0, especially if the Flink instance is exposed.
Exploit
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Flink