CVE-2020-1960
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/05/2020
Last modified:
07/11/2023
Description
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.1.0 (including) | 1.1.5 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.2.0 (including) | 1.2.1 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.3.0 (including) | 1.3.3 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.4.0 (including) | 1.4.2 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.5.0 (including) | 1.5.6 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.6.0 (including) | 1.6.4 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.7.0 (including) | 1.7.2 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.8.0 (including) | 1.8.3 (including) |
cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* | 1.9.0 (including) | 1.9.2 (including) |
cpe:2.3:a:apache:flink:1.10.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://lists.apache.org/thread.html/r23e559dee1e69741557b5fe431846de1f1a5981356d0ddb9482df88a%40%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/r26fcdd4fe288323006253437ebc4dd6fdfadfb5e93465a0e4f68420d%40%3Cuser-zh.flink.apache.org%3E
- https://lists.apache.org/thread.html/r28f17e564950d663e68cc6fe75756012dda62ac623766bb9bc5e7034%40%3Cissues.flink.apache.org%3E
- https://lists.apache.org/thread.html/r663cf0d5c386bba2f562d45ad484d786151a84f0b95e45e2b0fb8e50%40%3Cissues.flink.apache.org%3E