Skip to content
COOEY

EXPOSURES › CVE-2020-17519

CVE-2020-17519

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-17519 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatcheddata-breachaccess-control

Apache Flink's REST interface allows attackers to read any file on the JobManager's local filesystem due to improper access control.

This vulnerability enables unauthorized access to sensitive data stored on the JobManager's local filesystem, posing a significant risk to DIB organizations using Apache Flink for data processing. The improper access control flaw allows attackers to read any file, potentially exposing sensitive information and violating compliance requirements. DIB organizations should immediately patch their Apache Flink deployments and review their access control configurations to mitigate this risk.

Shame score — A critical access control vulnerability that allows file reading, though not directly RCE, poses significant data exposure risks and requires prompt remediation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.