SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-17519

Apache Flink Improper Access Control Vulnerability

KEVHIGH 7.5EPSS 97.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
97.86% probability · 100th percentile
CISA KEV
Listed 23 May 2024 · due 13 June 2024
Weakness
CWE-552
Affected
apache/flink
Source
security@apache.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/typ0h03zyfrzjqlnb7plh64df1g2383d; https://nvd.nist.gov/vuln/detail/CVE-2020-17519

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.