CVE-2020-17519
Apache Flink Improper Access Control Vulnerability
7.5
CVSS 3.1
97.8 %
EPSS (current)
2024-05-23
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Apache / Flink
Published: 2021-01-05 · Due (CISA): 2024-06-13
CWE: CWE-552 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2020/CVE-2020-17519.yaml | Apache Flink - Local File Inclusion | – |
| metasploit | auxiliary/scanner/http/apache_flink_jobmanager_traversal | auxiliary/scanner/http/apache_flink_jobmanager_traversal | 2021-01-05 |
| exploitdb | 49398 | Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit) | 2021-01-08 |
References only — no downloads or instructions.