Rewterz
Rewterz Threat Alert – Covid-19 Themed Malicious URLs
January 5, 2021
Rewterz
Rewterz Threat Alert – BITTER APT Group Active Again in South Asia
January 6, 2021

Rewterz Threat Advisory – CVE-2020-17519 – Apache Flink directory traversal

Severity

High

Analysis Summary

CVE-2020-17519

Apache Flink could allow a remote attacker to traverse directories on the system, caused by improper validation of user request by the REST API. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) to read arbitrary files on the system.

Impact

Obtain Information

Affected Vendors

Apache

Affected Products

  • Apache Flink 1.11.0
  • Apache Flink 1.11.1
  • Apache Flink 1.11.2

Remediation

Upgrade to the latest version of Apache Flink (1.11.3, 1.12.0 or later).