RE: CVE-2021-44228 - Log4j2 vulnerability

2022-01-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
gards, Suchithra From: David Morávek Sent: Sunday, January 9, 2022 12:11 AM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: Chesnay Schepler ; Martijn Visser ; Michael Guterl ; Parag Somani ; patrick.eif...@sony.com; Richard Deurwaarder ; User ; subharaj.ma...@gmail.com; swamy.haj...@gmail.com Su

RE: CVE-2021-44228 - Log4j2 vulnerability

2022-01-08 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, When can we expect the flink 1.12 releases with log4j 2.17.1? Thanks, Suchithra From: Martijn Visser Sent: Thursday, January 6, 2022 7:45 PM To: patrick.eif...@sony.com Cc: David Morávek ; swamy.haj...@gmail.com; subharaj.ma...@gmail.com; V N, Suchithra (Nokia - IN/Bangalore) ; Chesnay

RE: Suspected SPAM - RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-18 Thread V N, Suchithra (Nokia - IN/Bangalore)
From: V N, Suchithra (Nokia - IN/Bangalore) Sent: Saturday, December 18, 2021 9:20 PM To: Chesnay Schepler ; user Cc: Michael Guterl ; Richard Deurwaarder ; Parag Somani Subject: Suspected SPAM - RE: CVE-2021-44228 - Log4j2 vulnerability Hi, It seems there is high severity vulnerability in

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-18 Thread V N, Suchithra (Nokia - IN/Bangalore)
ursday, December 16, 2021 4:35 PM To: Parag Somani Cc: Michael Guterl ; V N, Suchithra (Nokia - IN/Bangalore) ; Richard Deurwaarder ; user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will announce the releases when the binaries are available. On 16/12/2021 05:37, Parag Somani wrote: Tha

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
of 1.12.6 only or we can expect both versions within ETA mentioned? From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:56 PM To: V N, Suchithra (Nokia - IN/Bangalore) ; Richard Deurwaarder ; user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability The current ETA is 40h for an official

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, Could you please tell when we can expect Flink 1.12.7 release? We are waiting for the CVE fix. Regards, Suchithra From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:04 PM To: Richard Deurwaarder Cc: user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will also update

RE: CVE-2021-44228 - Log4j2 vulnerability

2021-12-15 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, Could you please tell when we can expect Flink 1.12.7 release? We are waiting for the CVE fix. Regards, Suchithra From: Chesnay Schepler Sent: Wednesday, December 15, 2021 4:04 PM To: Richard Deurwaarder Cc: user Subject: Re: CVE-2021-44228 - Log4j2 vulnerability We will also update

RE: Suspected SPAM - RE: FW: Hadoop3 with Flink

2021-07-04 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, Could you please help on this? Regards, Suchithra -Original Message- From: V N, Suchithra (Nokia - IN/Bangalore) Sent: Wednesday, June 30, 2021 11:34 AM To: Yangze Guo ; user@flink.apache.org Subject: Suspected SPAM - RE: FW: Hadoop3 with Flink Hi Yangze Guo, Thanks for the

RE: FW: Hadoop3 with Flink

2021-06-29 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi Yangze Guo, Thanks for the reply. I am using flink in Kubernetes environment. Hence can you please suggest how to use hadoop3 with flink in k8s. Regards, Suchithra -Original Message- From: Yangze Guo Sent: Monday, June 28, 2021 3:16 PM To: V N, Suchithra (Nokia - IN/Bangalore) Cc

FW: Hadoop3 with Flink

2021-06-28 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, Can anyone please share inputs on this? Regards, Suchithra From: V N, Suchithra (Nokia - IN/Bangalore) Sent: Thursday, June 24, 2021 2:35 PM To: user@flink.apache.org Subject: Hadoop3 with Flink Hello, We are using Apache flink 1.12.3 and planning to use Hadoop 3 version. Could you please

Hadoop3 with Flink

2021-06-24 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using Apache flink 1.12.3 and planning to use Hadoop 3 version. Could you please suggest how to use Hadoop 3 with flink distribution. Regards, Suchithra

RE: Issue with onTimer method of KeyedProcessFunction

2021-06-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
= aggrRecord.get(); // Always get null value. Thanks, Suchithra From: JING ZHANG Sent: Wednesday, June 9, 2021 2:20 PM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: user@flink.apache.org; Jash, Shaswata (Nokia - IN/Bangalore) Subject: Re: Issue with onTimer method of KeyedProcessFunction Hi Suchithra

RE: Issue with onTimer method of KeyedProcessFunction

2021-06-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
= aggrRecord.get(); // Always get null value. Thanks, Suchithra From: JING ZHANG Sent: Wednesday, June 9, 2021 2:20 PM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: user@flink.apache.org; Jash, Shaswata (Nokia - IN/Bangalore) Subject: Re: Issue with onTimer method of KeyedProcessFunction Hi Suchithra

Issue with onTimer method of KeyedProcessFunction

2021-06-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using apache flink 1.7 and now trying to upgrade to flink 1.12.3 version. After upgrading to 1.12.3 version, the onTimer method of KeyedProcessFunction is not behaving correctly, the value of ReducingState and ValueState always return null. Could you please help in debugging th

Dependency vulnerabilities with flink 1.12.3

2021-05-22 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, Following dependency vulnerabilities found with flink 1.12.3 version. Please provide your input on this. 1. commons-io-2.7 Severity: High Description: Apache Commons IO contains a flaw that is due to the program failing to restrict which class can be ser

Stop command failure

2021-05-18 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, Stop command is failing with below error with apache flink 1.12.3 version. Could you pls help. log":"[Flink-RestClusterClient-IO-thread-2] org.apache.flink.shaded.netty4.io.netty.channel.AbstractChannel Force-closing a channel whose registration task was not accepted by an event loop: [id:

taskmanager initialization failed

2021-05-17 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, With flink 1.11.1 version, taskmanager initialization is failing with below error. Could you please help to debug the issue. log":"[main] org.apache.flink.runtime.io.network.netty.NettyConfig NettyConfig [server address: /0.0.0.0, server port: 4121, ssl enabled: false, memory segment size

Query on passing memory parameters

2021-05-10 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using Apache flink 1.12.1 version and using standalone-job.sh to start the per-job cluster mode flink. In the logs we could see some memory configurations parameters are being added as dynamic parameters. When checked the Java process system properties we can see the below output:

Query regarding flink metric types

2021-04-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi Community, Need some information regarding metrics type mentioned in flink documentation. https://ci.apache.org/projects/flink/flink-docs-stable/ops/metrics.html For the checkpoint metrics, below metrics are defined as of type gauge. As per my understanding gauge type is used to represent a v

RE: Need information on latency metrics

2021-03-05 Thread V N, Suchithra (Nokia - IN/Bangalore)
PM To: user@flink.apache.org Subject: Re: Need information on latency metrics Hi Suchithra, did you see this section in the docs? https://ci.apache.org/projects/flink/flink-docs-stable/ops/metrics.html#latency-tracking Regards, Timo On 05.03.21 15:31, V N, Suchithra (Nokia - IN/Bangalore)

Need information on latency metrics

2021-03-05 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, I am using flink 1.12.1 version and trying to explore latency metrics with Prometheus. I have enabled latency metrics by adding "metrics.latency.interval: 1" in flink-conf.yaml. I have submitted a flink streaming job which has Source->flatmap->process->sink which is chained into single task

RE: Flink cli Stop command exception

2020-12-10 Thread V N, Suchithra (Nokia - IN/Bangalore)
写道: Hi Suchithra, Have you ever checked job manager log to see whether the savepoint is triggered and why the savepoint failed to complete. Best Yun Tang From: V N, Suchithra (Nokia - IN/Bangalore) mailto:suchithra@nokia.com>> Sent: Wednesday, December 9, 2020 23

Flink cli Stop command exception

2020-12-09 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, I am running streaming flink job and I was using cancel command with savepoint to cancel the job. From flink 1.10 version stop command should be used instead of cancel command. But I am getting below error sometimes. Please let me know what might be the issue. {"host":"cancel1-flinkcli

RE: Dependency vulnerabilities with flink 1.11.1 version

2020-10-27 Thread V N, Suchithra (Nokia - IN/Bangalore)
Thanks Robert. Regards, Suchithra From: Robert Metzger Sent: Tuesday, October 27, 2020 9:10 PM To: Till Rohrmann Cc: V N, Suchithra (Nokia - IN/Bangalore) ; user@flink.apache.org Subject: Re: Dependency vulnerabilities with flink 1.11.1 version FYI: For the sake of completeness, I have added

Dependency vulnerabilities with flink 1.11.1 version

2020-10-22 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using Apache Flink 1.11.1 version. During our security scans following issues are reported by our scan tool. 1.Package : commons_codec-1.10 Severity: Medium Description: Apache Commons contains a flaw that is due to the Base32 codec decoding invalid strings instead of rejecting

Password usage in ssl configuration

2020-10-16 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, I have a query regarding the ssl configuration in flink. In flink with ssl enabled, flink-conf.yaml configuration file will contain the cleartext passwords for keystore and truststore files. Suppose if any attacker gains access to this configuration file, using these passwords keystore a

Dependency vulnerabilities with Apache Flink 1.10.1 version

2020-08-06 Thread V N, Suchithra (Nokia - IN/Bangalore)
Security Team Sent: Thursday, August 6, 2020 1:08 PM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: Jash, Shaswata (Nokia - IN/Bangalore) ; Prabhala, Anuradha (Nokia - IN/Bangalore) ; Badagandi, Srinivas B. (Nokia - IN/Bangalore) Subject: Re: Security vulnerabilities with Apache Flink 1.10.1

Per-job mode job restart and HA configuration

2020-08-03 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, I am using Flink version 1.10.1 in Kubernetes environment. In per-Job mode of flink, to achieve HA do we need zookeeper and HA parameters to restart the job? I am suspicious because job jar is part of the docker itself. Thanks, Suchithra

RE: Flink 1.8.1 HDFS 2.6.5 issue

2019-10-28 Thread V N, Suchithra (Nokia - IN/Bangalore)
Thanks for the information. Without setting such parameter explicitly, is there any possibility that it may work intermittently? From: Dian Fu Sent: Tuesday, October 29, 2019 7:12 AM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: user@flink.apache.org Subject: Re: Flink 1.8.1 HDFS 2.6.5 issue

RE: Flink 1.8.1 HDFS 2.6.5 issue

2019-10-28 Thread V N, Suchithra (Nokia - IN/Bangalore)
dfs.DFSOutputStream$DataStreamer.nextBlockOutputStream(DFSOutputStream.java:1357) at org.apache.hadoop.hdfs.DFSOutputStream$DataStreamer.run(DFSOutputStream.java:587) Regards, Suchithra From: Dian Fu Sent: Monday, October 28, 2019 5:40 PM To: V N, Suchithra (Nokia - IN/Bangalore) Cc: user@flink.apache.org Subject: Re:

Flink 1.8.1 HDFS 2.6.5 issue

2019-10-28 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hi, I am trying to execute Wordcount.jar in Flink 1.8.1 with Hadoop version 2.6.5. HDFS is enabled with Kerberos+SSL. While writing output to HDFS, facing the below exception and job will be failed. Please let me know if any suggestions to debug this issue. Caused by: org.apache.flink.runtime.

Apache flink 1.7.2 security issues

2019-08-13 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using Apache Flink 1.7.2 version. During our security scans following issues are reported by our scan tool. Please let us know your comments on these issues. [1] 150085 Slow HTTP POST vulnerability Severity Potential Vulnerability - Level 3 Group Information Disclosure Threat The

Apache flink 1.7.2 security issues

2019-08-11 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We are using Apache Flink 1.7.2 version. During our security scans following issues are reported by our scan tool. Please let us know your comments on these issues. [1] 150085 Slow HTTP POST vulnerability Severity Potential Vulnerability - Level 3 Group Information Disclosure Threat The

RE: Information required regarding SSL algorithms for Flink 1.5.x

2018-09-27 Thread V N, Suchithra (Nokia - IN/Bangalore)
Gentle reminder on this question. From: V N, Suchithra (Nokia - IN/Bangalore) Sent: Monday, September 24, 2018 3:56 PM To: user@flink.apache.org Subject: Information required regarding SSL algorithms for Flink 1.5.x Hello, We have a query regarding SSL algorithms available for Flink versions

OpenSSL use in Flink

2018-09-26 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, I have a query regarding OpenSSL usage in Flink. Please let me know if Flink uses OpenSSL and SSL_CTX API's. Thanks, Suchithra

Information required regarding SSL algorithms for Flink 1.5.x

2018-09-24 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, We have a query regarding SSL algorithms available for Flink versions. From the documents of Flink 1.6.0 we could see following SSL algorithms options are supported. security.ssl.algorithms: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_2