VYPR

Maven package

org.apache.flink/flink-runtime

pkg:maven/org.apache.flink/flink-runtime

Vulnerabilities (1)

  • CVE-2020-17518Jan 5, 2021
    affected >= 1.5.1, < 1.11.3fixed 1.11.3

    Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Fl