cve-2020-17518

HIGH CVSS 7.5 csaf_redhat
Description

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Timeline
Published
2020-01-01 00:00 UTC
Last Modified
2026-08-04
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-17518.json"
      }
    ],
    "title": "apache-flink: directory traversal attack allows remote file writing through the REST API",
    "tracking": {
      "current_release_date": "2026-08-04T21:44:36+00:00",
      "generator": {
        "date": "2026-08-04T21:44:36+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.8"
        }
      },
      "id": "CVE-2020-17518",
      "initial_release_date": "2020-01-01T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2020-01-01T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-04T15:54:34+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-04T21:44:36+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Integration Camel K 1",
                "product": {
                  "name": "Red Hat Integration Camel K 1",
                  "product_id": "red_hat_integration_camel_k_1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:integration:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Integration Camel K 1"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Integration Camel Quarkus 1",
                "product": {
                  "name": "Red Hat Integration Camel Quarkus 1",
                  "product_id": "red_hat_integration_camel_quarkus_1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_quarkus:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Integration Camel Quarkus 1"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Integration Camel Quarkus 2",
                "product": {
                  "name": "Red Hat Integration Camel Quarkus 2",
                  "product_id": "Red Hat Integration Camel Quarkus 2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_quarkus:2"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Integration",
                "product": {
                  "name": "Red Hat Integration",
                  "product_id": "Red Hat Integration",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:integration:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Integration"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7.9",
                "product": {
                  "name": "Red Hat Fuse 7.9",
                  "product_id": "Red Hat Fuse 7.9",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Fuse"
          },
          {
            "category": "product_version",
            "name": "flink",
            "product": {
              "name": "flink",
              "product_id": "flink",
              "product_identification_helper": {
                "purl": "pkg:golang/github.com/apache/beam/sdks/v2/go/pkg/beam/runners/flink?type=package"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "flink as a component of Red Hat Integration Camel K 1",
          "product_id": "red_hat_integration_camel_k_1:flink"
        },
        "product_reference": "flink",
        "relates_to_product_reference": "red_hat_integration_camel_k_1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "flink as a component of Red Hat Integration Camel Quarkus 1",
          "product_id": "red_hat_integration_camel_quarkus_1:flink"
        },
        "product_reference": "flink",
        "relates_to_product_reference": "red_hat_integration_camel_quarkus_1"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-17518",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "discovery_date": "2021-01-05T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_integration_camel_k_1:flink",
            "red_hat_integration_camel_quarkus_1:flink"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "1913312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "apache-flink: directory traversal attack allows remote file writing through the REST API",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Fuse 7.9",
          "Red Hat Integration",
          "Red Hat Integration Camel Quarkus 2"
        ],
        "known_not_affected": [
          "red_hat_integration_camel_k_1:flink",
          "red_hat_integration_camel_quarkus_1:flink"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2020-17518"
        },
        {
          "category": "external",
          "summary": "RHBZ#1913312",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1913312"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2020-17518",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-17518"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2020-17518",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-17518"
        }
      ],
      "release_date": "2021-01-05T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2021-08-11T18:21:58+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\n\nInstallation instructions are available from the Fuse 7.9.0 product\ndocumentation page:\nhttps://access.redhat.com/documentation/en-us/red_hat_fuse/7.9/",
          "product_ids": [
            "Red Hat Fuse 7.9"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:3140"
        },
        {
          "category": "vendor_fix",
          "date": "2021-08-18T09:13:12+00:00",
          "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "Red Hat Integration"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:3205"
        },
        {
          "category": "vendor_fix",
          "date": "2021-08-18T09:54:27+00:00",
          "details": "Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "Red Hat Integration Camel Quarkus 2"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:3207"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Fuse 7.9",
            "Red Hat Integration",
            "Red Hat Integration Camel Quarkus 2",
            "red_hat_integration_camel_k_1:flink",
            "red_hat_integration_camel_quarkus_1:flink"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "Red Hat Fuse 7.9",
            "Red Hat Integration",
            "Red Hat Integration Camel Quarkus 2",
            "red_hat_integration_camel_k_1:flink",
            "red_hat_integration_camel_quarkus_1:flink"
          ]
        }
      ],
      "title": "apache-flink: directory traversal attack allows remote file writing through the REST API"
    }
  ]
}
Enrichment data
View JSON API Download JSON