cve-2020-17519

HIGH cisa_known_exploited
Description

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

Timeline
Published
2024-05-23
Last Modified
2024-05-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 0.0,
  "datePublished": "2024-05-23",
  "dateUpdated": "2024-05-23",
  "description": "Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.",
  "dueDate": "2024-06-13",
  "id": "CVE-2020-17519",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/typ0h03zyfrzjqlnb7plh64df1g2383d; https://nvd.nist.gov/vuln/detail/CVE-2020-17519",
  "product": "Flink",
  "requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "severity": "HIGH",
  "source": "cisa_known_exploited",
  "title": "Apache Flink Improper Access Control Vulnerability",
  "vendor": "Apache"
}
Enrichment data
View JSON API Download JSON