When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6720 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. |
Github GHSA |
GHSA-hhm6-jjf4-6pm3 | Apache Airflow MySQL Provider is Vulnerable to SQL Injection |
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apache-airflow-providers-mysql |
|
| CPEs | cpe:2.3:a:apache:apache-airflow-providers-mysql:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache apache-airflow-providers-mysql |
Tue, 25 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 19 Mar 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 19 Mar 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. | |
| Title | Apache Airflow MySQL Provider: SQL injection in MySQL provider core function | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-03-25T17:45:20.580Z
Reserved: 2025-02-17T19:29:12.155Z
Link: CVE-2025-27018
Updated: 2025-03-19T19:02:38.085Z
Status : Analyzed
Published: 2025-03-19T09:15:14.457
Modified: 2025-06-03T21:11:28.860
Link: CVE-2025-27018
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA