VYPR
High severity7.5NVD Advisory· Published Jan 5, 2021· Updated Jun 17, 2026

CVE-2020-17518

CVE-2020-17518

Description

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.flink:flink-runtimeMaven
>= 1.5.1, < 1.11.31.11.3

Affected products

4

Patches

Vulnerability mechanics

References

50

News mentions

0

No linked articles in our index yet.