logo

CISA Warns of Actively Exploited Apache Flink Security Vulnerability

ID: ca4590e5-8759-595c-ab27-23752a23b955

STIX ID: report--ca4590e5-8759-595c-ab27-23752a23b955

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

CISA added Apache Flink vulnerability CVE-2020-17519 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; the flaw enables unauthenticated directory traversal to read arbitrary files from the JobManager REST interface and affects Flink 1.11.0–1.11.2, with fixes released in 1.11.3/1.12.0 and a federal remediation recommendation by June 13, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.