ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2020-17519

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17519
Unauthenticated Arbitrary File Read in Apache Flink JobManager REST Interface

CVE-2020-17519 is an improper access control flaw (CWE-552) in Apache Flink, introduced in version 1.11.0 and carried into 1.11.1 and 1.11.2, that allows unauthenticated attackers to read arbitrary files on the JobManager host. It is triggered over the network by sending crafted directory-traversal requests to the REST interface of the JobManager process, requiring no credentials or user interaction (CVSS 3.1: 7.5, AV:N/PR:N/UI:N). An attacker gains read access to any file on the local filesystem that the JobManager process can access, potentially exposing configuration files, secrets, and credentials. Any deployment running Flink 1.11.0 through 1.11.2 with the JobManager REST interface reachable by untrusted clients is affected. Exploitation is active: a public proof-of-concept exists, EPSS estimates a 97.9% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-05-23.

Do: Upgrade Flink to 1.11.3 or 1.12.0 (or later) per the vendor's guidance, prioritizing instances whose REST interface is reachable from untrusted networks, as required by the CISA KEV entry. If upgrading is not immediately possible, restrict access to the JobManager REST port with firewall or network ACL rules. Review JobManager access logs for traversal-style REST requests indicating prior file-read exploitation.

7.598% KEV PoC
  • Apache Flink 1.11.0, 1.11.1, and 1.11.2 (fixed in 1.11.3 and 1.12.0)
large≈ tens of thousands of internet-exposed Flink JobManager instances
Full article212 words · extracted from securityaffairs.com · click to collapse

CISA adds Apache Flink improper access control vulnerability to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a NextGen Healthcare Mirth Connect vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

The issue, tracked as CVE-2020-17519, is an improper access control vulnerability in Apache Flink.

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

An improper access control vulnerability occurs when an application or system does not adequately restrict user permissions, allowing unauthorized users to access resources, perform actions, or obtain data they should not be able to. This type of vulnerability can lead to unauthorized access, data breaches, and other security issues.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these vulnerabilities by June 13, 2024.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Apache Flink)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/163635/security/cisa-apache-flink-flaw-known-exploited-vulnerabilities-catalog.html