Impact
An attacker can inject arbitrary Teradata SQL through unvalidated Dag Params in the compute-cluster example DAG. This allows execution of dangerous data definition and manipulation statements under the connection associated with the task. The vulnerability arises from the provider's operators directly templating free-text Dag Params into DDL, enabling code execution without requiring Teradata credentials from the attacker.
Affected Systems
Apache Airflow Teradata provider users who deploy the compute-cluster example DAG, or variants copied from it, with any version of the provider before 3.7.0. The effect is specific to deployments that expose the example DAG; the provider's core operator code remains unchanged.
Risk and Exploitability
The CVSS score is 6.3, indicating a moderate severity. Because the description indicates the flaw requires a user with permission to trigger the DAG—not necessarily a database admin—the risk is high for organizations that enable low-trust execution roles. The exact EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of input validation combined with the potential to run arbitrary SQL indicates a severe threat. Attackers can manipulate the Dag Params to inject DDL and select arbitrary connections from the data source, enabling data exfiltration or structural changes in the Teradata environment.
OpenCVE Enrichment