[ 
https://issues.apache.org/jira/browse/FLINK-10303?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17328567#comment-17328567
 ] 

Flink Jira Bot commented on FLINK-10303:
----------------------------------------

This major issue is unassigned and itself and all of its Sub-Tasks have not 
been updated for 30 days. So, it has been labeled "stale-major". If this ticket 
is indeed "major", please either assign yourself or give an update. Afterwards, 
please remove the label. In 7 days the issue will be deprioritized.

> Fix critical vulnerabilities Python API
> ---------------------------------------
>
>                 Key: FLINK-10303
>                 URL: https://issues.apache.org/jira/browse/FLINK-10303
>             Project: Flink
>          Issue Type: Improvement
>          Components: API / Python
>    Affects Versions: 1.6.0
>            Reporter: Konstantin Knauf
>            Priority: Major
>              Labels: stale-major
>
> A user has reported two "critical" vulnerabilities in the Python API, which 
> we should probably fix: 
> * https://nvd.nist.gov/vuln/detail/CVE-2016-4000
> * https://cwe.mitre.org/data/definitions/384.html in 
> flink-streaming-python_2.11-1.6.0.jar <= pip-1.6-py2.py3-none-any.whl <= 
> sessions.py : [2.1.0, 2.6.0)
> For users, who don't need the Python API, an easy work-around is exclude the 
> flink-streaming-python_2.11.jar from the distribution. 
>  



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to