CVE-2025-27018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/03/2025
Last modified:
03/06/2025

Description

Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Apache Airflow MySQL Provider.<br /> <br /> When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.<br /> It could lead to data corruption, modification and others.<br /> This issue affects Apache Airflow MySQL Provider: before 6.2.0.<br /> <br /> Users are recommended to upgrade to version 6.2.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:apache-airflow-providers-mysql:*:*:*:*:*:*:*:* 6.2.0 (excluding)