
Apache Flink directory traversal vulnerability, allows remote file read/write via REST API Vulnerability ID: CVE-2020-17518
Vulnerability Description: CVE-2020-17518: Write remote files via REST API
Affected Versions: Flink 1.5.1-1.11.2
Safe Versions: Flink 1.11.3 or Flink 1.12.0
Flink 1.5.1 introduced a REST API that can copy arbitrary files to any location in the file system through maliciously modified HTTP headers.
Usage: Single: python CVE-2020-17518.py -u http://IP:port Batch: python CVE-2020-17518.py -f url.txt