CVE-2025-30473
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-30473 is a vulnerability affecting Apache Airflow Common SQL Provider before version 1.24.1. An SQL Injection issue was discovered in the application, allowing authenticated UI users to inject arbitrary SQL commands when triggering a DAG. This exposure occurred due to the use of the partition clause in SQLTableCheckOperator as a parameter, which was previously recommended. attackers could exploit this vulnerability to escalate privileges and execute unauthorized SQL commands, potentially leading to serious data breaches or system compromise. To mitigate this risk, users are strongly advised to upgrade to the latest version, 1.24.1, which includes the necessary patches to resolve the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Apache