CISA Warns of Active Exploits in Apache Flink and NextGen Healthcare Flaws

1 min read
Source: The Register
CISA Warns of Active Exploits in Apache Flink and NextGen Healthcare Flaws
Photo: The Register
TL;DR Summary

A three-year-old improper access control bug in Apache Flink, CVE-2020-17519, is being actively exploited, prompting the US government to add it to the Known Exploited Vulnerabilities Catalog. Federal agencies must patch or stop using the software by June 13, and all users should ensure they are updated and check for potential compromises. The flaw allows attackers to read any file on the JobManager's local filesystem via the REST interface, and its exploitation underscores the critical need for timely software updates.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

85%

51880 words

Want the full story? Read the original article

Read on The Register