Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
Exploits (16)
exploitdb
WORKING POC
VERIFIED
by SunCSR Team · rubywebappsjava
https://www.exploit-db.com/exploits/49398
nomisec
SCANNER
61 stars
by MrCl0wnLab · infoleak
https://github.com/MrCl0wnLab/SimplesApachePathTraversal
nomisec
WORKING POC
8 stars
by murataydemir · infoleak
https://github.com/murataydemir/CVE-2020-17519
nomisec
NO CODE
3 stars
by dolevf · infoleak
https://github.com/dolevf/apache-flink-directory-traversal.nse
nomisec
WORKING POC
1 stars
by yaunsky · infoleak
https://github.com/yaunsky/CVE-2020-17519-Apache-Flink
nomisec
WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/apache__flink_CVE-2020-17519_1-11-2
metasploit
WORKING POC
by 0rich1 - Ant Security FG Lab, Hoa Nguyen - Suncsr Team, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/apache_flink_jobmanager_traversal.rb
Nuclei Templates (1)
Apache Flink - Local File Inclusion
HIGHby pdteam
References (17)
Scores
CVSS v3
7.5
EPSS
0.9433
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Lab Environment
COMMUNITY
Community Lab
+12 more repos
Details
CISA KEV
2024-05-23
VulnCheck KEV
2021-04-12
InTheWild.io
2024-05-17
ENISA EUVD
EUVD-2021-0481
CWE
CWE-552
Status
published
Products (3)
apache/flink
1.11.0 - 1.11.3
org.apache.flink/flink-runtime_2.11
1.11.0 - 1.11.3Maven
org.apache.flink/flink-runtime_2.12
1.11.0 - 1.11.3Maven
Published
Jan 05, 2021
KEV Added
May 23, 2024
Tracked Since
Feb 18, 2026