[ 
https://issues.apache.org/jira/browse/FLINK-38193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18016872#comment-18016872
 ] 

Sergey Nuyanzin edited comment on FLINK-38193 at 9/8/25 8:11 AM:
-----------------------------------------------------------------

Merged as 
[f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25]
2.0: 
[427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2|https://github.com/apache/flink/commit/427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2]
2.1: 
[2af372b7361397ca501c4ec8a1f44b4ee62dc4a4|https://github.com/apache/flink/commit/2af372b7361397ca501c4ec8a1f44b4ee62dc4a4]


was (Author: sergey nuyanzin):
Merged as 
[f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25]

> Upgrade org.apache.commons:commons-lang3 from 3.12.0 to 3.18.0 to mitigate 
> CVE-2025-48924
> -----------------------------------------------------------------------------------------
>
>                 Key: FLINK-38193
>                 URL: https://issues.apache.org/jira/browse/FLINK-38193
>             Project: Flink
>          Issue Type: Improvement
>          Components: Connectors / Common, Connectors / FileSystem
>    Affects Versions: 2.1.0, 2.1.1
>            Reporter: Jakub Stejskal
>            Assignee: Jakub Stejskal
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 2.2.0
>
>
> Flink seems to be affected by 
> [CVE-2025-48924|https://nvd.nist.gov/vuln/detail/CVE-2025-48924]. This should 
> be fixable by bump commons-lang3 to 3.18 or newer.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to