Rewterz Threat Alert – Covid-19 Themed Malicious URLs
January 5, 2021Rewterz Threat Alert – BITTER APT Group Active Again in South Asia
January 6, 2021Rewterz Threat Alert – Covid-19 Themed Malicious URLs
January 5, 2021Rewterz Threat Alert – BITTER APT Group Active Again in South Asia
January 6, 2021Severity
High
Analysis Summary
CVE-2020-17519
Apache Flink could allow a remote attacker to traverse directories on the system, caused by improper validation of user request by the REST API. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) to read arbitrary files on the system.
Impact
Obtain Information
Affected Vendors
Apache
Affected Products
- Apache Flink 1.11.0
- Apache Flink 1.11.1
- Apache Flink 1.11.2
Remediation
Upgrade to the latest version of Apache Flink (1.11.3, 1.12.0 or later).