[
https://issues.apache.org/jira/browse/FLINK-38159?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Gyula Fora closed FLINK-38159.
------------------------------
Fix Version/s: kubernetes-operator-1.13.0
Assignee: David Kornel
Resolution: Fixed
merged to main 3069d5a922b2ded8ff1ebd93317f1d59d5cace64
> Update commons-lang3 to mitigate CVE-2025-48924
> -----------------------------------------------
>
> Key: FLINK-38159
> URL: https://issues.apache.org/jira/browse/FLINK-38159
> Project: Flink
> Issue Type: Improvement
> Components: Kubernetes Operator
> Affects Versions: kubernetes-operator-1.12.1
> Reporter: David Kornel
> Assignee: David Kornel
> Priority: Major
> Labels: pull-request-available
> Fix For: kubernetes-operator-1.13.0
>
>
> The Flink Kubernetes Operator is currently vulnerable to
> [CVE-2025-48924|https://nvd.nist.gov/vuln/detail/CVE-2025-48924].
> This should be fixable by upgrading to the latest version of the
> org.apache.commons:commons-lang3 dependency.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)