logo

Three-year-old Apache Flink flaw under active attack

ID: e29510e9-0b9b-5644-a1fa-1ba7c93f665e

STIX ID: report--e29510e9-0b9b-5644-a1fa-1ba7c93f665e

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-05-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

An improper access control vulnerability in Apache Flink (CVE-2020-17519) — which allows attackers to read any file on the JobManager's local filesystem via its REST interface — was fixed in 2021 but is now reported as being actively exploited and was added to CISA's Known Exploited Vulnerabilities catalog in May 2024; federal agencies must remediate or stop using affected versions by June 13, and all organizations are urged to patch and check for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.