CVE-2020-17518
- EPSS 93.37%
- Veröffentlicht 05.01.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 05:08:16
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. ...
CVE-2020-17519
- EPSS 94.38%
- Veröffentlicht 05.01.2021 12:15:12
- Zuletzt bearbeitet 13.02.2025 16:47:51
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files acc...
CVE-2020-1960
- EPSS 0.07%
- Veröffentlicht 14.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:44
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a...