vendor:
Flink
by:
0rich1 - Ant Security FG Lab, Hoa Nguyen - Suncsr Team
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Flink
Affected Version From: 1.11.0
Affected Version To: 1.11.2
Patch Exists: YES
Related CWE: CVE-2020-17519
CPE: a:apache:flink
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: php
2021
Apache Flink File Read Vulnerability
This module exploits an unauthenticated directory traversal vulnerability in Apache Flink version 1.11.0 (and released in 1.11.1 and 1.11.2 as well), allowing arbitrary file read with the web server privileges.
Mitigation:
Upgrade to Apache Flink version 1.11.3 or later.