Get the App
SLTechnology News&Howtos  ›  Servers  › 

Example Analysis of remote Code execution vulnerability caused by Apache Flink arbitrary Jar package upload

Shulou Source: shulou.com Published: 2022-05-31 16:31:43 09月21日 Update

Editor to share with you Apache Flink arbitrary Jar package upload led to remote code execution vulnerabilities example analysis, I believe that most people do not know much about it, so share this article for your reference, I hope you will learn a lot after reading this article, let's go to know it!

Vulnerability description

Apache Flink is an open source platform for distributed streams and batch data. The core of Flink is a streaming data streaming engine, which provides data distribution, communication and fault tolerance for distributed computing on data streams. Flink builds batches on top of the flow engine, covering local iteration support, managed memory, and program optimization. Recently, security researchers have found that apache flink allows arbitrary jar packages to be uploaded, resulting in remote code execution.

Vulnerability level

High risk

Scope of influence

Apache Flink

Tags: Vulnerabilities data code suggestions articles examples analysis success content distribution engine data flow files detection not much people memory functions lists most Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi Docker Microsoft Huawei Shulou Technology