Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process (aka local file inclusion).
id: CVE-2020-17519
info:
name: Apache Flink - Local File Inclusion
author: pdteam
severity: h
...