Логотип exploitDog
bind:CVE-2020-17518
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-17518

Количество 3

Количество 3

redhat логотип

CVE-2020-17518

около 5 лет назад

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2020-17518

около 5 лет назад

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-7q5g-gph2-4rc6

почти 4 года назад

Upload of file to arbitrary path in Apache Flink

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-17518

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVSS3: 7.5
94%
Критический
около 5 лет назад
nvd логотип
CVE-2020-17518

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVSS3: 7.5
94%
Критический
около 5 лет назад
github логотип
GHSA-7q5g-gph2-4rc6

Upload of file to arbitrary path in Apache Flink

CVSS3: 7.5
94%
Критический
почти 4 года назад

Уязвимостей на страницу