VYPR

Bitnami package

flink

pkg:bitnami/flink

Vulnerabilities (4)

  • CVE-2026-35194HigMay 15, 2026
    affected >= 1.15.0, < 1.20.4fixed 1.20.4

    Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1

  • CVE-2020-17519KEVJan 5, 2021
    affected >= 1.11.0, < 1.11.3fixed 1.11.3

    A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager proc

  • CVE-2020-17518Jan 5, 2021
    affected >= 1.5.1, < 1.11.3fixed 1.11.3

    Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Fl

  • CVE-2020-1960May 14, 2020
    affected >= 1.1.0, < 1.1.6fixed 1.1.6

    A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port configured via metrics.r