ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Warns of Actively Exploited Apache Flink Security Vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2020-17519CVE-2020-28188CVE-2020-29227

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17519
Unauthenticated Arbitrary File Read in Apache Flink JobManager REST Interface

CVE-2020-17519 is an improper access control flaw (CWE-552) in Apache Flink, introduced in version 1.11.0 and carried into 1.11.1 and 1.11.2, that allows unauthenticated attackers to read arbitrary files on the JobManager host. It is triggered over the network by sending crafted directory-traversal requests to the REST interface of the JobManager process, requiring no credentials or user interaction (CVSS 3.1: 7.5, AV:N/PR:N/UI:N). An attacker gains read access to any file on the local filesystem that the JobManager process can access, potentially exposing configuration files, secrets, and credentials. Any deployment running Flink 1.11.0 through 1.11.2 with the JobManager REST interface reachable by untrusted clients is affected. Exploitation is active: a public proof-of-concept exists, EPSS estimates a 97.9% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-05-23.

Do: Upgrade Flink to 1.11.3 or 1.12.0 (or later) per the vendor's guidance, prioritizing instances whose REST interface is reachable from untrusted networks, as required by the CISA KEV entry. If upgrading is not immediately possible, restrict access to the JobManager REST port with firewall or network ACL rules. Review JobManager access logs for traversal-style REST requests indicating prior file-read exploitation.

7.598% KEV PoC
  • Apache Flink 1.11.0, 1.11.1, and 1.11.2 (fixed in 1.11.3 and 1.12.0)
large≈ tens of thousands of internet-exposed Flink JobManager instances
CVE-2020-28188
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

NVD description · AI analysis pending
9.897% PoC ×2
  • terra-master tos
CVE-2020-29227
An issue was discovered in Car Rental Management System 1.0.

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

NVD description · AI analysis pending
9.817% PoC
  • car rental management system project car rental management system
Full article245 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 23, 2024Threat Intelligence / Vulnerability,

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting Apache Flink, an open-source, unified stream-processing and batch-processing framework, to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Tracked as CVE-2020-17519, the issue relates to a case of improper access control that could allow an attacker to read any file on the local filesystem of the JobManager through its REST interface.

This also means that a remote unauthenticated attacker could send a specially crafted directory traversal request that could permit unauthorized access to sensitive information.

The vulnerability, which impacts Flink versions 1.11.0, 1.11.1, and 1.11.2, was addressed in January 2021 in versions 1.11.3 or 1.12.0.

The exact nature of the attacks exploiting the flaw is presently unknown, although Palo Alto Networks Unit 42 warned of extensive in-the-wild abuse between November 2020 and January 2021.

"Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021," security researchers Lei Xu, Yue Guan, and Vaibhav Singhal noted in April 2021.

In light of the active exploitation of CVE-2020-17519, federal agencies are recommended to apply the latest fixes by June 13, 2024, to safeguard their networks against active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-apache.html