EXPOSURES › CVE-2020-17519
CVE-2020-17519
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Flink's REST interface allows attackers to read any file on the JobManager's local filesystem due to improper access control.
This vulnerability enables unauthorized access to sensitive data stored on the JobManager's local filesystem, posing a significant risk to DIB organizations using Apache Flink for data processing. The improper access control flaw allows attackers to read any file, potentially exposing sensitive information and violating compliance requirements. DIB organizations should immediately patch their Apache Flink deployments and review their access control configurations to mitigate this risk.
Shame score — A critical access control vulnerability that allows file reading, though not directly RCE, poses significant data exposure risks and requires prompt remediation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.