CVE-2025-27018
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
19/03/2025
Last modified:
03/06/2025
Description
Improper Neutralization of Special Elements used in an SQL Command (&#39;SQL Injection&#39;) vulnerability in Apache Airflow MySQL Provider.<br />
<br />
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.<br />
It could lead to data corruption, modification and others.<br />
This issue affects Apache Airflow MySQL Provider: before 6.2.0.<br />
<br />
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:apache-airflow-providers-mysql:*:*:*:*:*:*:*:* | 6.2.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page