Description
Apache Flink is an open-source, unified stream-processing and batch-processing framework developed by the Apache Software Foundation.
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process.
Remediation
All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed.
References
Related Vulnerabilities
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.13)
WordPress Plugin Adifier System Multiple Vulnerabilities (3.1.3)
WordPress Plugin Post PDF Export Local File Inclusion (1.0.1)
WordPress Plugin NextGEN Gallery-WordPress Gallery Directory Traversal (2.1.9)
WordPress Plugin Nelio AB Testing Directory Traversal (4.4.4)