CVE-2025-62228
Published: Oct 9, 2025
Modified: Nov 4, 2025
Description
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Flink CDC | affected 3.0.0 - <= 3.4.0 |
Apache Software Foundation | Apache Flink CDC | affected 3.0.0 - <= 3.4.0 |
Apache Software Foundation | Apache Flink CDC | affected 3.0.0 - <= 3.4.0 |
Apache Software Foundation | Apache Flink CDC | affected 3.0.0 - <= 3.4.0 |
Apache Software Foundation | Apache Flink CDC | affected 3.3.0 - <= 3.4.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now