Apache Apache-Airflow-Providers-Mysql vulnerabilities
2 known vulnerabilities affecting apache/apache-airflow-providers-mysql.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-27018MEDIUMCVSS 6.3fixed in 6.2.02025-03-19
CVE-2025-27018 [MEDIUM] CWE-89 CVE-2025-27018: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modifica
ghsanvdosv
CVE-2023-22884CRITICALCVSS 9.8fixed in 4.0.02023-01-21
CVE-2023-22884 [CRITICAL] CWE-77 CVE-2023-22884: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
ghsanvdosv