Details
-
Improvement
-
Status: Closed
-
Minor
-
Resolution: Invalid
-
1.6.0
-
None
Description
A user has reported two "critical" vulnerabilities in the Python API, which we should probably fix:
- https://nvd.nist.gov/vuln/detail/CVE-2016-4000
- https://cwe.mitre.org/data/definitions/384.html in flink-streaming-python_2.11-1.6.0.jar <= pip-1.6-py2.py3-none-any.whl <= sessions.py : [2.1.0, 2.6.0)
For users, who don't need the Python API, an easy work-around is exclude the flink-streaming-python_2.11.jar from the distribution.