← Πίσω στην αναζήτηση CVE

CVE-2026-40564

Apache Flink Kubernetes Operator

Περιγραφή

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a user with CR create permissions read files from the operator pod-s filesystem and pull content from any backing store reachable through Flink-s pluggable filesystem layer and access them through the submitted Flink job. Furthermore for fetching from http/https addresses there is currently no allowlist on the URI scheme, no host check, no IP-range restriction, and no protection against pointing the URI at internal or link-local addresses.This issue affects Apache Flink Kubernetes Operator: from 1.3.0 before 1.15.0. Users are recommended to upgrade to version 1.15.0, which fixes the issue.

CVSS 6.5EPSS 0.49%Κίνδυνος 0.68
Προβολή πηγής
Δημοσίευση
2026-05-26 16:16:24
Επηρεαζόμενες εκδόσεις
>=1.3.0,<1.15.0
Τύπος
Package
Τελευταία τροποποίηση
2026-07-24 11:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N