PT-2021-10097 · Apache · Apache Flink

0Rich1

+1

·

Published

2021-01-05

·

Updated

2025-10-27

·

CVE-2020-17519

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Apache Flink versions 1.11.0 through 1.11.2
Description: A change introduced in Apache Flink allows attackers to read any file on the local filesystem of the JobManager through the REST interface. Access is restricted to files accessible by the JobManager process. The vulnerability was actively exploited between November 2020 and January 2021, and is now listed in CISA’s Known Exploited Vulnerabilities catalog. A proof-of-concept (PoC) exploit is available, demonstrating a directory traversal attack via the /jobmanager/logs endpoint.
Recommendations: Upgrade to Apache Flink version 1.11.3 or 1.12.0.

Exploit

Fix

Path traversal

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2025-09901
BIT-FLINK-2020-17519
CVE-2020-17519
GHSA-395W-QHQR-9FR6

Affected Products

Apache Flink