CVE-2020-1960: Apache Flink JMX information disclosure vulnerability
Severity: Medium
(CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H)
Vendor:
The Apache Software Foundation
Versions Affected:
Flink 1.1.0 to 1.1.5
Flink 1.2.0 to 1.2.1
Flink 1.3.0 to 1.3.3
Flink 1.4.0 to 1.4.2
Flink 1.5.0 to
Might be related to this
https://issues.apache.org/jira/browse/FLINK-10135
--
Sent from: http://apache-flink-user-mailing-list-archive.2336050.n4.nabble.com/
Hello,
I've upgraded my cluster to version 1.5.3 from 1.4.2. After the upgrade I
notice that some of the metrics reported via JMX, like the number of running
jobs, are missing.
I've listed all of the domains and this is what I have:
/$>domains
#following domains are available
JMImplementation
co
29, 2016 at 4:36 PM, Chesnay Schepler <
>> ches...@apache.org> wrote:
>>
>>> Hello,
>>>
>>> can you post the jmx config entries and give us more details on how you
>>> want to access it?
>>>
>>> Regards,
>>> Chesna
ards,
Chesnay
On 29.08.2016 12:09, Sreejith S wrote:
Hi All,
I am using Flink-1.1.1 and i enabled JMX metrics in
configuration file. In the task manger log i can see JMX is
running.
Is this metrics exposed only through Flink Metrics API
.08.2016 12:09, Sreejith S wrote:
>>
>> Hi All,
>>
>> I am using Flink-1.1.1 and i enabled JMX metrics in configuration file.
>> In the task manger log i can see JMX is running.
>>
>> Is this metrics exposed only through Flink Metrics API's ?
>>
MX metrics in configuration file. In
> the task manger log i can see JMX is running.
>
> Is this metrics exposed only through Flink Metrics API's ?
>
> I tried to connect to flink JMX URL using normal javax , but connections
> getting refused.
>
> Thanks,
>
> --
>
this metrics exposed only through Flink Metrics API's ?
I tried to connect to flink JMX URL using normal javax , but
connections getting refused.
Thanks,
--
*Sreejith.S*
https://github.com/srijiths/
http://srijiths.wordpress.com/
**tweet2sree@twitter <http://tweet2Sree>
Hi All,
I am using Flink-1.1.1 and i enabled JMX metrics in configuration file. In
the task manger log i can see JMX is running.
Is this metrics exposed only through Flink Metrics API's ?
I tried to connect to flink JMX URL using normal javax , but connections
getting refused.
T