apache-flink: JMX information disclosure vulnerability
Published May 14, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.86%
Description
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Affected products
- Vendor n/a Product Apache Flink Defaultunknown
Affected
- Apache Flink 1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Apache Flink | unknown | Affected
|
- ≥ 1.1.0 · ≤ 1.1.5
- ≥ 1.2.0 · ≤ 1.2.1
- ≥ 1.3.0 · ≤ 1.3.3
- ≥ 1.4.0 · ≤ 1.4.2
- ≥ 1.5.0 · ≤ 1.5.6
- ≥ 1.6.0 · ≤ 1.6.4
- ≥ 1.7.0 · ≤ 1.7.2
- ≥ 1.8.0 · ≤ 1.8.3
- ≥ 1.9.0 · ≤ 1.9.2
- 1.10.0
No data.
Red Hat Fuse 7.8.0
camel-flink
Fixed · RHSA-2020:5568
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.8.0 | camel-flink | Fixed | RHSA-2020:5568 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2020-1960 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1848126 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0970 Advisory
- https://github.com/advisories/GHSA-6g88-99wj-8mgg Advisory
- https://lists.apache.org/thread.html/r23e559dee1e69741557b5fe431846de1f1a5981356d0ddb9482df88a%40%3Cdev.flink.apache.org%3E x_refsource_MISCMailing ListPatchVendor Advisory
- https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache.org%3E x_refsource_MISC
- https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d@%3Cuser-zh.flink.apache.org%3E
- https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034@%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r663cf0d5c386bba2f562d45ad484d786151a84f0b95e45e2b0fb8e50%40%3Cissues.flink.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r663cf0d5c386bba2f562d45ad484d786151a84f0b95e45e2b0fb8e50@%3Cissues.flink.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-1960
- https://www.cve.org/CVERecord?id=CVE-2020-1960
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub