CVE-2025-27018 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG…
Medium CVSS: 6.3

CVE-2025-27018

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.

When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Vendor
Apache
Product
Apache-airflow-providers-mysql
CWE
CWE-89
Yayın Tarihi
2025-03-19 09:15:14
Güncelleme
2025-06-03 21:11:28
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar