AI description
CVE-2025-62228 describes a SQL injection vulnerability found in Apache Flink CDC version 3.4.0. This flaw allows for the injection of SQL commands through the use of maliciously crafted identifiers, such as database or table names. While the vulnerability requires a logged-in database user to initiate the attack, it is recommended that users update to Apache Flink CDC version 3.5.0 to mitigate this issue.
- Description
- Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- flink_cdc
CVSS 4.0
- Type
- Secondary
- Base score
- 5.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Amber
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security@apache.org
- CWE-89
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
8
108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806
@BugBunny_ai
27 Aug 2026
4618 Impressions
0 Retweets
18 Likes
6 Bookmarks
2 Replies
1 Quote
CVE-2025-62228 Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through onl… https://t.co/VwddzYdrGH
@CVEnew
9 Oct 2025
297 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:flink_cdc:3.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C168575C-C471-47F8-AC40-8AAB071A7C4E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]