CVE-2020-17519
CWE-552
90.0
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.
Source: NVD
Signals
- CVSS
- 7.5
- High · v3.1
- EPSS
- 97.80%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since May 2024
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-552
- Published
- 5 Jan 2021
- Last modified 27 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2020-17519Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time