SCA: security update for org.apache.flink:flink-runtime_2.11, org.apache.flink:flink-runtime_2.12 (GHSA-395w-qhqr-9fr6)

high Tenable Cloud Security Plugin ID 409422

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to
read any file on the local filesystem of the JobManager through the REST interface of the JobManager
process. Access is restricted to files accessible by the JobManager process. All users should upgrade to
Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit
b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master. (CVE-2020-17519)

See Also

https://github.com/advisories/GHSA-395w-qhqr-9fr6

Plugin Details

Severity: High

ID: 409422

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.9

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2020-17519

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/6/2021

Vulnerability Publication Date: 1/5/2021

CISA Known Exploited Vulnerability Due Dates: 6/13/2024

Exploitable With

Elliot (Apache Flink Directory Traversal)

Reference Information

CVE: CVE-2020-17519