Apache Flink Improper Access Control Vulnerability
Apache · Flink
Date added (CISA)
2024-05-23
Remediation due
2024-06-13
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.