Details
-
Technical Debt
-
Status: Closed
-
Major
-
Resolution: Duplicate
-
None
-
None
-
None
Description
kryo 2.24 is several years out of date and has a deserialization vulnerability associated with it. Please update to current.
Attachments
Issue Links
- duplicates
-
FLINK-24736 Non vulenerable jar files for Apache Flink 1.14.4
- Closed
- is duplicated by
-
FLINK-3154 Update Kryo version from 2.24.0 to latest Kryo LTS version
- Reopened