[ https://issues.apache.org/jira/browse/FLINK-38193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18016872#comment-18016872 ]
Sergey Nuyanzin edited comment on FLINK-38193 at 9/8/25 8:11 AM: ----------------------------------------------------------------- Merged as [f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25] 2.0: [427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2|https://github.com/apache/flink/commit/427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2] 2.1: [2af372b7361397ca501c4ec8a1f44b4ee62dc4a4|https://github.com/apache/flink/commit/2af372b7361397ca501c4ec8a1f44b4ee62dc4a4] was (Author: sergey nuyanzin): Merged as [f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25] > Upgrade org.apache.commons:commons-lang3 from 3.12.0 to 3.18.0 to mitigate > CVE-2025-48924 > ----------------------------------------------------------------------------------------- > > Key: FLINK-38193 > URL: https://issues.apache.org/jira/browse/FLINK-38193 > Project: Flink > Issue Type: Improvement > Components: Connectors / Common, Connectors / FileSystem > Affects Versions: 2.1.0, 2.1.1 > Reporter: Jakub Stejskal > Assignee: Jakub Stejskal > Priority: Major > Labels: pull-request-available > Fix For: 2.2.0 > > > Flink seems to be affected by > [CVE-2025-48924|https://nvd.nist.gov/vuln/detail/CVE-2025-48924]. This should > be fixable by bump commons-lang3 to 3.18 or newer. -- This message was sent by Atlassian Jira (v8.20.10#820010)