← Vulnerability feed

Vulnerability record · CVE-2020-17519 · published 5 January 2021

CVE-2020-17519: Apache Flink JobManager REST interface arbitrary file read

Apache · Flink

A change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to files the JobManager process can access. It matters because the JobManager REST endpoint is often network-reachable and the flaw requires no authentication, exposing configuration, credentials and other sensitive files.

7.5 CVSS 3.1 High CISA KEV since 23 May 2024 EPSS 98% · top 0.1% CWE-552 · CWE-552
7.5CVSS 3.1 base score, v2 5.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
39References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network file read with a public exploit, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.

What it is

A change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to files the JobManager process can access. It matters because the JobManager REST endpoint is often network-reachable and the flaw requires no authentication, exposing configuration, credentials and other sensitive files.

Impact

An unauthenticated attacker gains read access to arbitrary files readable by the JobManager process, which can leak secrets, configuration and data used to pivot further into the cluster.

Attack surface

Reached over the network via the JobManager REST interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the REST port can attempt it.

Exploitation

CISA added it to KEV on 2024-05-23 with a 2024-06-13 remediation due date, and EPSS is 0.978 (99.9th percentile); a public exploit reference is tagged, so exploitation is expected and active.

What to do

  • Upgrade Apache Flink to 1.11.3 or 1.12.0, which contain the fix (commit b561010b0ee741543c3953306037f00d7a9f0801).
  • If immediate upgrade is not possible, restrict network access to the JobManager REST interface to trusted hosts only.
  • Run the JobManager under a least-privilege account so files it can read are limited.
  • Monitor vendor and CISA KEV guidance and apply the required action by the 2024-06-13 due date.

Detection

  • Review JobManager REST access logs for unusual or traversal-style file path requests from unexpected source IPs.
  • Alert on requests to the JobManager REST port from hosts outside the expected management network.
  • Hunt for signs of file content exfiltration or unexpected reads of sensitive files by the JobManager process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-17519 to the Known Exploited Vulnerabilities catalog on 23 May 2024 as "Apache Flink Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 June 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/160849/Apache-Flink-1.11.0-Arbitrary-File-Read-Directory-Traversal.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/01/05/2 Mailing ListThird Party Advisory
https://lists.apache.org/thread.html/r0a433be10676f4fe97ca423d08f914e0ead341c901216f292d2bbe83%40%3Cissues.flink.apache. Mailing List
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r229167538863518738e02f4c1c5a8bb34c1d45dadcc97adf6676b0c1%40%3Cdev.flink.apache.org Issue Tracking
https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache Issue Tracking
https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r2fc60b30557e4a537c2a6293023049bd1c49fd92b518309aa85a0398%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r4e1b72bfa789ea5bc20b8afe56119200ed25bdab0eb80d664fa5bfe2%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cannounce.apache.org% Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cuser.flink.apache.or Issue Tracking
https://lists.apache.org/thread.html/r88b55f3ebf1f8f4e1cc61f030252aaef4b77060b56557a243abb92a1%40%3Cissues.flink.apache. Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r88f427865fb6aa6e6378efe07632a1906b430365e15e3b9621aabe1d%40%3Cissues.flink.apache. Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org% Mailing ListNot Applicable
https://lists.apache.org/thread.html/ra8c96bf3ccb4e491f9ce87ba35f134b4449beb2a38d1ce28fd89001f%40%3Cdev.flink.apache.org Issue Tracking
http://packetstormsecurity.com/files/160849/Apache-Flink-1.11.0-Arbitrary-File-Read-Directory-Traversal.html ExploitThird Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/01/05/2 Mailing ListThird Party Advisory
https://lists.apache.org/thread.html/r0a433be10676f4fe97ca423d08f914e0ead341c901216f292d2bbe83%40%3Cissues.flink.apache. Mailing List
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r229167538863518738e02f4c1c5a8bb34c1d45dadcc97adf6676b0c1%40%3Cdev.flink.apache.org Issue Tracking
https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache Issue Tracking
https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r2fc60b30557e4a537c2a6293023049bd1c49fd92b518309aa85a0398%40%3Cissues.flink.apache. Issue Tracking
https://lists.apache.org/thread.html/r4e1b72bfa789ea5bc20b8afe56119200ed25bdab0eb80d664fa5bfe2%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cannounce.apache.org% Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cdev.flink.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r6843202556a6d0bce9607ebc02e303f68fc88e9038235598bde3b50d%40%3Cuser.flink.apache.or Issue Tracking
https://lists.apache.org/thread.html/r88b55f3ebf1f8f4e1cc61f030252aaef4b77060b56557a243abb92a1%40%3Cissues.flink.apache. Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r88f427865fb6aa6e6378efe07632a1906b430365e15e3b9621aabe1d%40%3Cissues.flink.apache. Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org% Mailing ListNot Applicable
https://lists.apache.org/thread.html/ra8c96bf3ccb4e491f9ce87ba35f134b4449beb2a38d1ce28fd89001f%40%3Cdev.flink.apache.org Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17519 US Government Resource

Track CVE-2020-17519 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-35194Apache flink code injection vulnerabilityCode injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…EPSS 0.66%7.5CVE-2020-17518Apache Flink REST handler path traversal allows arbitrary file writeApache Flink 1.5.1 introduced a REST handler that writes an uploaded file to an arbitrary location on the local file system when a maliciously modifi…EPSS 50%analysed4.7CVE-2020-1960Apache flink vulnerabilityA vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.…EPSS 0.86%7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed7.8CVE-2017-16651Roundcube Webmail file disclosure via attachment pluginRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows an authenticated user to read arbitrary files on the host filesyst…KEVEPSS 46%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2020-17519), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.