Customer 360
Fraud detection
Dynamic pricing
Extract, Transform, Load (ETL)
Security Information and Event Management (SIEM)
AI and machine learning (ML)
Ververica was tasked with providing a solution to support Airbus, a leading aircraft manufacturer, in deploying their Apache Flink® jobs at scale.
Booking.com, a leading travel ecosystem serving both partners and travelers, faced challenges with processing security data
FinTech Studios leverages Ververica Platform to ingest millions of research, news and regulatory sources in real-time
One Mount Group set up a Platform-as-a-Service offering for Apache Flink to enable the company’s tech team to deploy and manage Flink applications
XM Cyber utilizes its Apache Flink® (Flink) applications to ensure unlimited scaling for customers, in real-time, regardless of data volumes
Humn.ai uses Ververica Platform and Apache Flink to build a Machine Learning-based platform producing dynamic risk assessment models
Over 100,000 lessons per day! How does VIPKID solve the problem of online education real-time live broadcast interaction?
Learn how Weibo uses Apache Flink and Ververica Platform to unify offline and online data processing and run Machine Learning pipelines at scale.
Ververica was tasked with providing a solution to support Airbus, a leading aircraft manufacturer, in deploying their Apache Flink® jobs at scale.
Booking.com, a leading travel ecosystem serving both partners and travelers, faced challenges with processing security data
FinTech Studios leverages Ververica Platform to ingest millions of research, news and regulatory sources in real-time
One Mount Group set up a Platform-as-a-Service offering for Apache Flink to enable the company’s tech team to deploy and manage Flink applications
A Remote Code Execution (RCE) vulnerability was discovered in the popular Java logging library, Log4j. It is tracked via CVE-2021-44228 and is known as Log4Shell. This is a serious vulnerability that affects many software products and online services.
Apache Flink 1.11+ is affected by both vulnerabilities. Apache Flink 1.10 and earlier versions are not affected by this vulnerability.
All Ververica Platform components besides Apache Flink are unaffected as they are using Logback instead of Log4j. In the context of Log4Shell, a related - less severe - vulnerability has also been identified in Logback. This vulnerability requires writing access to the Logback configuration file, which should not be the case in typical Ververica Platform deployments.
Following the emergency releases of Apache Flink which upgraded Log4j to 2.16.0, we have just released new versions of our distribution of Apache Flink for Flink 1.10 to Flink 1.14:
In contrast to Apache Flink 1.10, Ververica’s distribution of Apache Flink 1.10 is affected by Log4Shell because it is already using Log4j2 whereas upstream Apache Flink 1.10 is still using Log4j1.
In addition, we have released Ververica Platform 2.5.3 and Ververica Platform 2.6.1 which reference the updated Flink images in their configuration and — just in case — include an upgraded version of Logback.
We recommend any users of Ververica Platform 2.5 and Ververica Platform 2.6 to upgrade as soon as possible.
We also recommend any user of Ververica Platform to upgrade all of their Deployments to use the newly released versions of Apache Flink regardless of which version of Ververica Platform they are using. Please check this documentation on how to add new Flink images to the Ververica Platform configuration. Please check the release notes of Ververica Platform 2.5.3 and Ververica Platform 2.6.1 as well as the respective documentation for a complete list of available images.
We’ve identified all internal, internet-facing services that were using Log4j2 and implemented upgrades, and recommended mitigation measures.
We are working with our sub-processors to ensure they remediate any vulnerabilities in their environments. These sub-processors are primarily related to customer incident response (Zendesk, Pagerduty).
In case of questions please get in touch or reach out to your account manager.
Introducing the next evolution in streaming joins: Apache Fluss offers ze...
End the batch vs streaming divide. Flink-powered lakehouse with 5-10× fas...
Discover how Apache Fluss™ transforms Ververica's Unified Streaming Data ...
Discover VERA-X, the groundbreaking native vectorized engine for Apache F...