unsubscribe
\ ]

On Thu, Oct 9, 2025 at 6:36 PM Leonard Xu <[email protected]> wrote:

> Severity:
>
> Affected versions:
>
> - Apache Flink CDC (org.apache.flink:flink-connector-mysql-cdc) 3.0.0
> through 3.4.0
> - Apache Flink CDC (org.apache.flink:flink-connector-sqlserver-cdc) 3.0.0
> through 3.4.0
> - Apache Flink CDC (org.apache.flink:flink-connector-db2-cdc) 3.0.0
> through 3.4.0
> - Apache Flink CDC (org.apache.flink:flink-connector-oracle-cdc) 3.0.0
> through 3.4.0
> - Apache Flink CDC
> (org.apache.flink:flink-cdc-pipeline-connector-oceanbase) 3.3.0 through
> 3.4.0
>
> Description:
>
> Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via
> maliciously crafted identifiers eg. crafted database name or crafted table
> name. Even through only the logged-in database user can trigger the attack,
> we recommend users update Flink CDC version to 3.5.0 which address this
> issue.
>
> Credit:
>
> intSheep (reporter)
> Mapta/BugBunny_ai (reporter)
>
> References:
>
> https://flink.apache.org/
> https://www.cve.org/CVERecord?id=CVE-2025-62228
>
>

Reply via email to