CVE-2020-17518 is a critical vulnerability affecting Apache Flink versions 1.5.1 through 1.11.2, allowing an unauthenticated attacker to write arbitrary files to any location on the local file system via a maliciously crafted HTTP header. With a CVSS score of 7.5 (HIGH), this vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on integrity, potentially leading to system compromise. While not currently listed on CISA's KEV catalog, public exploit intelligence indicates the availability of Nuclei templates for exploitation, and its high EPSS score suggests a high probability of future exploitation. Despite this, there is currently no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5.1, < 1.11.3CPE matchmatch criteria | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.