PT-2021-10096 · Apache · Apache Flink

·

CVE-2020-17518

·

Published

2021-01-05

·

Updated

2024-03-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Apache Flink versions 1.5.1
Description: A REST handler in Apache Flink allows writing an uploaded file to any location on the local file system through a maliciously modified HTTP HEADER. This issue enables files to be written to any location accessible by the software.
Recommendations: For Apache Flink version 1.5.1, upgrade to Flink 1.11.3 or 1.12.0, especially if the Flink instance is exposed.

Exploit

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-FLINK-2020-17518
CVE-2020-17518
GHSA-7Q5G-GPH2-4RC6

Affected Products

Apache Flink