GHSA-6g88-99wj-8mgg
MODERATECVE-2020-1960A vulnerability in Apache Flink where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reportername>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to
- Affected
- < 1.9.2, = 1.10.0
- Fixed in
- 1.9.3
- Weakness
- CWE-74
- Published
- 2021-05-21
- Source
- github