Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.

When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6720 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Github GHSA Github GHSA GHSA-hhm6-jjf4-6pm3 Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache-airflow-providers-mysql
CPEs cpe:2.3:a:apache:apache-airflow-providers-mysql:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache apache-airflow-providers-mysql

Tue, 25 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
References

Wed, 19 Mar 2025 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Title Apache Airflow MySQL Provider: SQL injection in MySQL provider core function
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-03-25T17:45:20.580Z

Reserved: 2025-02-17T19:29:12.155Z

Link: CVE-2025-27018

cve-icon Vulnrichment

Updated: 2025-03-19T19:02:38.085Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-19T09:15:14.457

Modified: 2025-06-03T21:11:28.860

Link: CVE-2025-27018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.