[
https://issues.apache.org/jira/browse/FLINK-38193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18016872#comment-18016872
]
Sergey Nuyanzin edited comment on FLINK-38193 at 9/8/25 8:11 AM:
-----------------------------------------------------------------
Merged as
[f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25]
2.0:
[427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2|https://github.com/apache/flink/commit/427355e9b4ecb40e4e6cd1b87b32a5a20ff1d3d2]
2.1:
[2af372b7361397ca501c4ec8a1f44b4ee62dc4a4|https://github.com/apache/flink/commit/2af372b7361397ca501c4ec8a1f44b4ee62dc4a4]
was (Author: sergey nuyanzin):
Merged as
[f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25|https://github.com/apache/flink/commit/f4bdad4dfbfdef3d1c3d4dafd0771244dc40cb25]
> Upgrade org.apache.commons:commons-lang3 from 3.12.0 to 3.18.0 to mitigate
> CVE-2025-48924
> -----------------------------------------------------------------------------------------
>
> Key: FLINK-38193
> URL: https://issues.apache.org/jira/browse/FLINK-38193
> Project: Flink
> Issue Type: Improvement
> Components: Connectors / Common, Connectors / FileSystem
> Affects Versions: 2.1.0, 2.1.1
> Reporter: Jakub Stejskal
> Assignee: Jakub Stejskal
> Priority: Major
> Labels: pull-request-available
> Fix For: 2.2.0
>
>
> Flink seems to be affected by
> [CVE-2025-48924|https://nvd.nist.gov/vuln/detail/CVE-2025-48924]. This should
> be fixable by bump commons-lang3 to 3.18 or newer.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)