boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2020-17519

Apache Flink directory traversal attack: reading remote files through the REST API
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .9781   99.9   YES
AFFECTED
  Product       Versions                         Fixed
  Apache Flink  Apache Flink 1.11.0 to 1.11.2 –  —
TIMELINE
  Aug 12  Reserved by apache
  Jan 5   Published (CNA: apache)
  May 23  Added to CISA KEV, remediation due 2024-06-13
CWE-552 · CNA: apache · CVSS v3.1 · 17 references · KEV due June 13, 2024

Description

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 12, 2020ReservedReserved by apache
January 5, 2021PublishedPublished (CNA: apache)
May 23, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-06-13

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache Flink—Apache Flink 1.11.0 to 1.11.2—

Weaknesses

CWE-552

References (17)

Related

Authoritative record: CVE-2020-17519 at cve.org

Vendors: apache

Weaknesses: CWE-552

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2020-17519 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.