Files or Directories Accessible to External Parties Affecting org.apache.flink:flink-kubernetes-operator-api package, versions [1.3.0,1.15.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEFLINK-17116507
  • published1 Jun 2026
  • disclosed26 May 2026
  • creditAndrea Cosentino

Introduced: 26 May 2026

NewCVE-2026-40564  (opens in a new tab)
CWE-552  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade org.apache.flink:flink-kubernetes-operator-api to version 1.15.0 or higher.

Overview

Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties via the jarURI parameter in FlinkSessionJob's validateSessionJob(), which is not properly validated. A user with Custom Resource create permissions can access arbitrary files from the operator pod's filesystem with file:// scheme URLs, or retrieve content from any accessible backing store by submitting a crafted Flink job. Additionally, by specifying http/https addresses, an attacker can make requests to internal or link-local network resources due to the absence of URI scheme allowlisting, host checks, or IP-range restrictions.

CVSS Base Scores

version 4.0
version 3.1