CVE-2020-17519 Details
Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
A directory traversal vulnerability has been identified in Apache Flink versions 1.11.0, 1.11.1, and 1.11.2. This vulnerability allows attackers to read any file on the local filesystem of the JobManager through the REST interface, accessing files that are accessible by the JobManager process.
Users are advised to upgrade to Apache Flink versions 1.11.3 or 1.12.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 24, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache Flink Improper Access Control Vulnerability | May 23, 2024 | Jun 13, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache flink | >= 1.11.0, < 1.11.3 |
CPE
Remediation
| |
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 14, 2024 | Modified Analysis | [email protected] |
| Jul 3, 2024 | CVE Modified | CISA-ADP |
| Jun 10, 2024 | Modified Analysis | [email protected] |
| May 23, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Mar 17, 2021 | Modified Analysis | [email protected] |
| Mar 2, 2021 | CVE Modified | [email protected] |
| Feb 24, 2021 | CVE Modified | [email protected] |
| Feb 1, 2021 | Modified Analysis | [email protected] |
| Jan 26, 2021 | CVE Modified | [email protected] |
| Jan 15, 2021 | CVE Modified | [email protected] |
| Jan 13, 2021 | CVE Modified | [email protected] |
| Jan 11, 2021 | CVE Modified | [email protected] |
| Jan 11, 2021 | CVE Modified | [email protected] |
| Jan 11, 2021 | CVE Modified | [email protected] |
| Jan 8, 2021 | CVE Modified | [email protected] |
| Jan 8, 2021 | Initial Analysis | [email protected] |
| Jan 8, 2021 | Initial Analysis | [email protected] |
| Jan 6, 2021 | CVE Modified | [email protected] |
| Jan 5, 2021 | CVE Modified | [email protected] |
| Jan 5, 2021 | CVE Modified | [email protected] |
| Jan 5, 2021 | CVE Modified | [email protected] |