A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-17519

Apache Flink Improper Access Control Vulnerability

Published
2024-05-23
Modified
2026-07-31
Sources
cisa-kev

Summary

Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.