Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Flink Stateful Functions
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41834 1 Apache 1 Flink Stateful Functions 2023-12-10 N/A 6.1 MEDIUM
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser. Users should upgrade to Apache Flink Stateful Functions version 3.3.0.