maven package report

Is org.apache.flink:flink-runtime_2.11 safe?

1 known vulnerability, worst severity HIGH.

cvss
9.1

how bad it is if exploited, out of 10

epss
97.8%

chance of exploitation in the next 30 days

xyz score
6.7

CyberXYZ composite, and a working exploit is published

fig. 01 — GHSA-395w-qhqr-9fr6, the advisory selected below

// advisories

GHSA-395w-qhqr-9fr6

HIGHCVE-2020-17519

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in c

Affected
>= 1.11.0, < 1.11.3
Fixed in
1.11.3
Weakness
CWE-22
Published
2021-01-06
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:46 UTC. The most recent advisory here was published 2021-01-06. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.flink:flink-runtime_2.11 safe? maven package security report | CyberXYZ