Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Moderate severity
GitHub Reviewed
Published
Mar 19, 2025
to the GitHub Advisory Database
•
Updated Mar 25, 2025
Description
Published by the National Vulnerability Database
Mar 19, 2025
Published to the GitHub Advisory Database
Mar 19, 2025
Reviewed
Mar 19, 2025
Last updated
Mar 25, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
References