CISA Warns that Apache Flink Vulnerability from 4 Years Ago is Still Being Actively Exploited

Published:

spot_img

Recent Discovery of Critical Apache Flink Vulnerability and Active Exploitation by Cyber Actors

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has raised alarms over a four-year-old security flaw in Apache Flink, a popular open-source framework for stream-processing and batch-processing. The flaw, identified as CVE-2020-17519, allows unauthorized access to sensitive information due to improper access control.

CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog after evidence of active exploitation was observed. The agency warns that vulnerabilities like the one in Apache Flink are frequently targeted by malicious cyber actors and pose significant risks to federal enterprises.

The flaw, present in versions 1.11.0, 1.11.1, and 1.11.2 of Apache Flink, enables remote attackers to access files on the local JobManager filesystem through specially crafted directory traversal requests. While specific details of ongoing exploitation campaigns remain unclear, the bug has been acknowledged by project maintainers and has been exploited for at least four years.

Mitigation measures have been put in place, with the Apache Software Foundation releasing patches in January 2021. CISA has mandated federal agencies to apply these patches by June 13, 2024, under the Binding Operational Directive to protect agency networks from active threats.

The discovery of this vulnerability underscores the importance of timely updates and patches for widely deployed open-source projects. Organizations are urged to follow vendor instructions for mitigations or discontinue the use of affected products if fixes are not available. This incident serves as a reminder of the constant vigilance required to safeguard against cyber threats in today’s digital landscape.

spot_img

Related articles

Recent articles

Webinar: Uncovering Suspicious APK Files in Wedding Card and Loan App Scams

The surge of malicious APK files in cyber fraud schemes, such as fake wedding invitations and instant loan applications, has become a growing concern....

Skylon Partners with COBNB to Launch COBNB+ Featuring L’Occitane en Provence Hotel Amenities

Skylon Partners with COBNB for a Luxurious Hospitality Experience in Kuala Lumpur Introduction to the New Partnership In an exciting development for the hospitality scene in...

Understanding CISA KEV: Key Insights and Tools for Security Teams

Understanding the CISA Known Exploited Vulnerability (KEV) Catalog The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerability (KEV) catalog, a resource designed...

Dark Web Leak Sparks WFH Job Scams; Prayagraj Police Freeze ₹2 Crore in Fraudulent Funds

Rising Cybercrime in Prayagraj: A New Target Shifting Tactics of Cybercriminals In Prayagraj, the landscape of cybercrime is evolving. Previously, scammers predominantly targeted victims through enticing...