SQL Injection Vulnerability in Apache Flink CDC Product by Apache
CVE-2025-62228

5.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2025

What is CVE-2025-62228?

Apache Flink CDC version 3.4.0 is susceptible to a SQL injection vulnerability, allowing attackers to exploit crafted database or table names. Although this can only be triggered by a logged-in database user, it poses significant security risks. Users are strongly advised to update to Flink CDC version 3.5.0, which resolves this vulnerability and enhances overall database security.

Affected Version(s)

Apache Flink CDC 3.0.0 <= 3.4.0

Apache Flink CDC 3.0.0 <= 3.4.0

Apache Flink CDC 3.0.0 <= 3.4.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

intSheep
Mapta/BugBunny_ai
.
CVE-2025-62228 : SQL Injection Vulnerability in Apache Flink CDC Product by Apache