Vulnerability record · CVE-2020-17519 · published 5 January 2021
CVE-2020-17519: Apache Flink JobManager REST interface arbitrary file read
Apache · Flink
A change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to files the JobManager process can access. It matters because the JobManager REST endpoint is often network-reachable and the flaw requires no authentication, exposing configuration, credentials and other sensitive files.
Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityUnauthenticated network file read with a public exploit, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.
What it is
A change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to files the JobManager process can access. It matters because the JobManager REST endpoint is often network-reachable and the flaw requires no authentication, exposing configuration, credentials and other sensitive files.
Impact
An unauthenticated attacker gains read access to arbitrary files readable by the JobManager process, which can leak secrets, configuration and data used to pivot further into the cluster.
Attack surface
Reached over the network via the JobManager REST interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the REST port can attempt it.
Exploitation
CISA added it to KEV on 2024-05-23 with a 2024-06-13 remediation due date, and EPSS is 0.978 (99.9th percentile); a public exploit reference is tagged, so exploitation is expected and active.
What to do
- Upgrade Apache Flink to 1.11.3 or 1.12.0, which contain the fix (commit b561010b0ee741543c3953306037f00d7a9f0801).
- If immediate upgrade is not possible, restrict network access to the JobManager REST interface to trusted hosts only.
- Run the JobManager under a least-privilege account so files it can read are limited.
- Monitor vendor and CISA KEV guidance and apply the required action by the 2024-06-13 due date.
Detection
- Review JobManager REST access logs for unusual or traversal-style file path requests from unexpected source IPs.
- Alert on requests to the JobManager REST port from hosts outside the expected management network.
- Hunt for signs of file content exfiltration or unexpected reads of sensitive files by the JobManager process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-17519 to the Known Exploited Vulnerabilities catalog on 23 May 2024 as "Apache Flink Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 June 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-17519 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17519), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.