Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhm6-jjf4-6pm3

Опубликовано: 19 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

Apache Airflow MySQL Provider is Vulnerable to SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.

When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.

Пакеты

Наименование

apache-airflow-providers-mysql

pip
Затронутые версииВерсия исправления

< 6.2.0

6.2.0

EPSS

Процентиль: 56%
0.00333
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.3
nvd
11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

EPSS

Процентиль: 56%
0.00333
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-89