GHSA-6g88-99wj-8mgg · Severity: medium · Ecosystem: maven — Command injection in Apache Flink
A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.reporter.reporter_name>.port, an attacker with local access to the machine and JMX port can execute a man-in-the-middle attack using a specially crafted request to rebind the JMXRMI registry to one under the attacker's control. This compromises any connection established to the process via JMX, allowing extraction of credentials and any other transferred data.
Conclusion & alert: CVE-2020-1960 is rated Low Risk (38.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.86%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.10% | 0.86% | +0.77% |
| 2 | 2025-03-17 | 0.04% | 0.10% | +0.05% |
| 3 | 2023-03-07 | — | 0.04% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.7 | 3.1 | MEDIUM |
|
1.0 | 3.6 | [email protected] |
| 1.9 | 2.0 | LOW |
|
3.4 | 2.9 | [email protected] |
GHSA-6g88-99wj-8mgg · Severity: medium · Ecosystem: maven — Command injection in Apache Flink
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-1960 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | flink | >= 1.1.0, <= 1.1.5 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.2.0, <= 1.2.1 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.3.0, <= 1.3.3 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.4.0, <= 1.4.2 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.5.0, <= 1.5.6 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.6.0, <= 1.6.4 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.7.0, <= 1.7.2 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.8.0, <= 1.8.3 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | >= 1.9.0, <= 1.9.2 | cpe:2.3:a:apache:flink:*:*:*:*:*:*:*:* |
| apache | flink | 1.10.0 | cpe:2.3:a:apache:flink:1.10.0:-:*:*:*:*:*:* |