Known vulnerabilities in Flink
Vendor:
Apache Foundation
Software:
Flink
Software CPE:
cpe:2.3:a:apache_foundation:flink:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
4
Public exploits:
3
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.3.0
2.1.3
1.20.5
2.2.1
2.1.2
2.0.2
1.20.4
2.2.0
2.1.1
2.0.1
1.20.3
2.1.0
1.20.2
1.19.3
2.0.0
1.20.1
1.19.2
1.20.0
1.19.1
1.19.0
1.18.1
1.16.3
1.17.2
1.18.0
1.17.1
1.16.2
1.17.0
1.15.4
1.16.1
1.15.3
1.16.0
1.14.6
1.15.2
1.15.1
1.14.5
1.14.4
1.13.6
1.14.3
1.14.2
1.13.5
1.12.7
1.11.6
0.7.0
0.6
0.5
0.4
1.13.4
1.14.1
1.15.0
1.13.3
1.14.0
1.12.5
1.11.4
1.13.2
1.13.1
1.12.4
1.13.0
1.12.3
1.12.2
1.12.1
1.10.3
1.12.0
1.11.3
1.11.2
1.11.1
1.11.0
1.10.2
1.10.1
1.10.0
1.9.3
1.9.2
1.9.1
1.9.0
1.8.3
1.8.2
1.8.1
1.8.0
1.7.2
1.7.1
1.7.0
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.2
1.4.1
1.4.0
1.3.3
1.3.2
1.3.1
1.3.0
1.2.1
1.2.0
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.3
1.0.2
1.0.1
1.0.0
0.10.2
0.10.1
0.10.0
0.9.1
0.9.0
0.8.1
0.8.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU109015 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2020-1960 |
CWE-74 | Low | 1.9.3, 1.10.1 | 13.05.2025 |
SB2020051447 SB2025051321 |
||
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | 1.11.6, 1.13.4, 1.14.1, 1.15.0 | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |
||
| #VU49272 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-17518 |
CWE-22 | Medium | 1.11.3 | 05.01.2021 |
SB2021010507 |
||
| #VU49273 - Exposure of sensitive information to an unauthorized actor CVE-2020-17519 |
CWE-200 | Medium | 1.11.3 | 05.01.2021 |
SB2021010507 |