Hi!
Thank you for reporting this!
At the moment, the Flink REST endpoint is not secure in the way that you
can expose it publicly. After all, you can submit Flink jobs to it which by
definition support executing arbitrary code.
Given that access to the REST endpoint allows by design arbitrary cod
Hello,
We are using Apache Flink 1.7.2 version. During our security scans following
issues are reported by our scan tool. Please let us know your comments on these
issues.
[1] 150085 Slow HTTP POST vulnerability
Severity Potential Vulnerability - Level 3
Group Information Disclosure
Threat
The