CVE-2025-62228

🟡 Monitoruj

Wstrzyknięcie SQL w Apache Flink CDC umożliwia atakującym manipulację danymi.

CVSS
8.8
EPSS
0.5%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.

sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2025-10-09 14:15:55 UTC
Ostatnia modyfikacja (NVD)2026-10-08 13:10:00 UTC
Referencje