Vulnerability record · CVE-2020-17518 · published 5 January 2021
CVE-2020-17518: Apache Flink REST handler path traversal allows arbitrary file write
Apache · Flink
Apache Flink 1.5.1 introduced a REST handler that writes an uploaded file to an arbitrary location on the local file system when a maliciously modified HTTP header is supplied. Because the write path is not constrained, an unauthenticated remote user can place files anywhere the Flink process can reach, which matters for any Flink instance exposed to a network.
Description
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file write with a high EPSS score and a straightforward network vector, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Apache Flink 1.5.1 introduced a REST handler that writes an uploaded file to an arbitrary location on the local file system when a maliciously modified HTTP header is supplied. Because the write path is not constrained, an unauthenticated remote user can place files anywhere the Flink process can reach, which matters for any Flink instance exposed to a network.
Impact
An attacker gains the ability to write files to arbitrary locations accessible by the Flink process, which can lead to overwriting configuration or dropping executable content and potentially to code execution depending on deployment. The CVSS vector confirms high integrity impact with no confidentiality or availability impact.
Attack surface
Reached over the network through the Flink REST interface; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required. Any Flink instance whose REST endpoint is exposed is directly reachable.
Exploitation
CVE-2020-17518 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.50 probability (98.8th percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory and mailing-list only, with no public exploit tag supplied.
What to do
- Upgrade Apache Flink to 1.11.3 or 1.12.0, which contain the fix from commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4.
- If immediate upgrade is not possible, restrict network access to the Flink REST endpoint to trusted hosts only.
- Run the Flink process with least privilege and a restricted filesystem so arbitrary writes cannot reach sensitive paths.
- Monitor and audit the Flink REST port for unexpected inbound connections and unusual file creation events.
Detection
- Alert on HTTP requests to the Flink REST endpoint containing unusual or attacker-controlled header values, especially those influencing file paths.
- Monitor filesystem writes in directories owned by the Flink process for unexpected new or modified files.
- Baseline normal Flink REST traffic and flag anomalous upload or file-write requests from unfamiliar source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-17518 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17518), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.