Information disclosure in Flink - CVE-2020-17519
Published: January 5, 2021 / Updated: August 1, 2025
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to application allows to read arbitrary files on the system of the JobManager through the REST interface of the JobManager process. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
How to mitigate CVE-2020-17519
Links to Public Exploits and PoC-codes
- Exploit #11828 - CVE-2020-17519 (CVE-2020-17519) (August 1, 2025)
- Exploit #8066 - CVE-2020-17519 () (June 22, 2022)
- Exploit #7442 - CVE-2020-17519 () (March 8, 2022)
- Exploit #7003 - apacheflink----POC (apache flink目录遍历(CVE-2020-17519)) (November 11, 2021)
- Exploit #5620 - Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit) (June 17, 2021)
- Exploit #5385 - Apache Flink JobManager Traversal (May 9, 2021)
- Exploit #5291 - CVE-2020-17519 (CVE-2020-17519 Cheetah) (April 13, 2021)
- Exploit #5180 - westone-CVE-2020-17519-scanner (A vulnerability scanner that detects CVE-2020-17519 vulnerabilities.) (February 25, 2021)
- Exploit #5039 - Flink- (CVE-2020-17519; Apache Flink 任意文件读取; 批量检测) (January 18, 2021)
- Exploit #5033 - CVE-2020-17519-Exp (CVE-2020-17519 EXP) (January 18, 2021)
- Exploit #5031 - CVE-2020-17519-Apache-Flink (CVE-2020-17519; Apache Flink 任意文件读取; 批量检测) (January 18, 2021)
- Exploit #5014 - CVE-2020-17519 (CVE-2020-17519) (January 11, 2021)
- Exploit #5012 - CVE-2020-17519 ([CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read) (January 11, 2021)
- Exploit #5004 - CVE-2020-17519 () (January 6, 2021)
- Exploit #5001 - CVE-2020-17519 (Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)) (January 6, 2021)
- Exploit #4999 - apache-flink-directory-traversal.nse (Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script) (January 6, 2021)