Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.
When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user.
This allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have.
This issue affects Apache Airflow Common SQL Provider: before 1.24.1.
Users are recommended to upgrade to version 1.24.1, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache airflow Common Sql Provider |
|
CPEs | cpe:2.3:a:apache:airflow_common_sql_provider:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache airflow Common Sql Provider |
Mon, 07 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 07 Apr 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 07 Apr 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user. This allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have. This issue affects Apache Airflow Common SQL Provider: before 1.24.1. Users are recommended to upgrade to version 1.24.1, which fixes the issue. | |
Title | Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection | |
Weaknesses | CWE-89 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-04-07T08:31:57.220Z
Updated: 2025-04-08T03:56:18.413Z
Reserved: 2025-03-22T12:17:36.698Z
Link: CVE-2025-30473

Updated: 2025-04-07T09:04:16.647Z

Status : Analyzed
Published: 2025-04-07T09:15:16.667
Modified: 2025-04-11T12:59:03.450
Link: CVE-2025-30473

No data.