¡¾·ì϶¹«¸æ¡¿CVE-2020-17518 Apache FlinkËÁÒâÎļþдÈë·ì϶

°ä²¼¹¦·ò 2021-01-06

0x00 ·ì϶¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Apache Flink

CVE-2020-17518

ËÁÒâÎļþдÈë

¸ßΣ

ÊÇ

CVE-2020-17519

ËÁÒâÎļþ¶ÁÈ¡

¸ßΣ

ÊÇ

0x01 ·ì϶ÏêÇé

 

image.png

 

Apache FlinkÊÇÓÉApacheÈí¼þ»ù½ð»á¿ª·¢µÄ¿ªÔ´Á÷´¦Öÿò¼Ü£¬ÆäÖ÷ÌâÊÇÓÃJavaºÍScala±àдµÄÉ¢²¼Ê½Êý¾ÝÁ÷ÒýÇæ¡£

2021Äê01ÔÂ05ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËApache FlinkÖеÄÁ½¸ö°²È«·ì϶£¨CVE-2020-17518ºÍCVE-2020-17519£©¡£

Apache FlinkËÁÒâÎļþдÈë·ì϶£¨CVE-2020-17518£©

Apache Flink 1.5.1ÒýÈëÁËREST´¦Ö÷¨Ê½£¬ÓÉÓÚÖ°ÄÜÉÏ´æÔÚȱµã£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄHTTP HEADER½«¶ñÒâÎļþдÈëµ½±¾µØÎļþϵͳÉϵÄËÁÒâµØÎ»£¬²¢¿Éͨ¹ýFlink ½Ó¼û¡£

Ó°ÏìÁìÓò£º

Apache Flink 1.5.1-1.11.2

 

Apache FlinkËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2020-17519£©

ÓÉÓÚApache Flink 1.11.0ÖÐÒýÈëÁËÒ»Ïî²»°²È«µÄ¸ü¸Ä£¬ÔÊÐí¹¥»÷Õßͨ¹ýJobManager¹ý³ÌµÄREST½Ó¿Ú¶ÁÈ¡±¾µØÎļþϵͳÉϵÄÈκÎÎļþ£¬ µ«½öÏÞÓÚ½Ó¼ûJobManager¹ý³Ì¿É½Ó¼ûµÄÎļþ¡£¹¥»÷Õß¿Éͨ¹ýREST APIʹÓÃ../ʵÏÖĿ¼±éÀú¡£

Ó°ÏìÁìÓò£º

Apache Flink 1.11.0¡¢1.11.1¡¢1.11.2

 

0x02 ´ëÖý¨Òé

ĿǰApacheÒѾ­½¨¸´ÁËÓйطì϶£¬½¨Òé¸üÐÂÖÁFlink 1.11.3»ò1.12.0¡£

ÏÂÔØÁ´½Ó£º

https://flink.apache.org/zh/downloads.html


0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCAGr9p8Co+adXuNzmHmG+o0uE6TMFGQqGdq80o1icRRnkKAZpEA@mail.gmail.com%3E

http://mail-archives.apache.org/mod_mbox/www-announce/202101.mbox/%3CCAGr9p8BZ+sMtZTNaU569f+8398WJr4k64WMDdSVaysgPy=HY2g@mail.gmail.com%3E

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17518

 

0x04 ¹¦·òÏß

2021-01-05  Apache°ä²¼°²È«²¼¸æ

2021-01-06  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png