cbcvebase.
CVE-2025-27018
published 2025-03-19

CVE-2025-27018: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG…

medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

Affected

16 ranges
VendorProductVersion rangeFixed in
apacheairflow>= 3.0.0 < 3.2.23.2.2
apacheapache-airflow-providers-mysql< 6.2.06.2.0
apacheapache-airflow-providers-mysql>= 0 < 6.2.06.2.0
apache_software_foundationapache_airflow>= 3.0.0 < 3.2.23.2.2
msrcazl3_hyperv-daemons_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_hyperv-daemons_6.6.35.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_hyperv-daemons_5.15.158.1-1_on_cbl_mariner_2.0
msrccbl2_hyperv-daemons_5.15.180.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.153.1-2_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.158.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64