BIT-flink-2020-17519

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/flink/BIT-flink-2020-17519.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-flink-2020-17519
Aliases
Published
2024-03-06T10:51:56.799Z
Modified
2024-06-12T07:54:49.981Z
Summary
[none]
Details

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / flink

Package

Name
flink
Purl
pkg:bitnami/flink

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.11.0
Fixed
1.11.3