Apache.Flink.JobManager.Arbitrary.Path.Traversal
Description
This indicates an attack attempt to exploit a Path Traversal Vulnerability in Apache Flink.
This vulnerability is due to improper handling of the request parameters in the vulnerable application. A remote attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted server. Successful exploitation of the vulnerability could lead to disclosure of sensitive information which may be used to facilitate further exploitation.
Affected Products
Apache Flink version 1.11.0
Apache Flink version 1.11.1
Apache Flink version 1.11.2
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://flink.apache.org/downloads.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2021-04-28 | 18.069 | Sig Added |
2021-02-22 | 17.020 | Default_action:pass:drop |
2021-01-27 | 17.006 | |
2021-01-21 | 17.005 | |
2021-01-20 | 17.003 |