Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqm3-w3p6-xjgm | Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers |
Wed, 03 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache flink Cdc
|
|
| CPEs | cpe:2.3:a:apache:flink_cdc:3.4.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache flink Cdc
|
|
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache flink |
|
| Vendors & Products |
Apache
Apache flink |
Thu, 09 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue. | |
| Title | Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC: SQL injection via maliciously crafted identifiers | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:14:15.721Z
Reserved: 2025-10-09T02:20:34.825Z
Link: CVE-2025-62228
Updated: 2025-11-04T21:14:15.721Z
Status : Analyzed
Published: 2025-10-09T14:15:55.533
Modified: 2025-12-03T21:48:36.607
Link: CVE-2025-62228
No data.
OpenCVE Enrichment
Updated: 2025-10-10T11:17:54Z
Github GHSA