CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
- Published
- Jan 5, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- Jan 8, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
Sources
13- CVE-2020-17519Scanner
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
- CVE-2020-17519Exploit
Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving log files from vulnerable targets.
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.