CVE-2025-62228

Published Oct 9, 2025

Last updated 9 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-62228 describes a SQL injection vulnerability found in Apache Flink CDC version 3.4.0. This flaw allows for the injection of SQL commands through the use of maliciously crafted identifiers, such as database or table names. While the vulnerability requires a logged-in database user to initiate the attack, it is recommended that users update to Apache Flink CDC version 3.5.0 to mitigate this issue.

Description
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.
Source
security@apache.org
NVD status
Analyzed
Products
flink_cdc

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Amber
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@apache.org
CWE-89

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

8

Configurations