CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
7.5
HIGH
CVSS 3.1
⚠ KEVEPSS 97.9%
描述
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
如何修補 CVE-2020-17519
要修補 CVE-2020-17519,請將受影響套件升級到下列已修補版本。
- —升級至 1.11.3 或更新版本
- —升級至 1.11.3 或更新版本
- —升級至 1.11.3 或更新版本
CVE-2020-17519 正在被利用嗎?
是 — CVE-2020-17519 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(3)
- >= 1.11.0, < 1.11.3
- >= 1.11.0, < 1.11.3
- >= 1.11.0, < 1.11.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H |