CVE-2025-30473

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 11, 2025
CWE ID 89

Summary

CVE-2025-30473 is a vulnerability affecting Apache Airflow Common SQL Provider before version 1.24.1. An SQL Injection issue was discovered in the application, allowing authenticated UI users to inject arbitrary SQL commands when triggering a DAG. This exposure occurred due to the use of the partition clause in SQLTableCheckOperator as a parameter, which was previously recommended. attackers could exploit this vulnerability to escalate privileges and execute unauthorized SQL commands, potentially leading to serious data breaches or system compromise. To mitigate this risk, users are strongly advised to upgrade to the latest version, 1.24.1, which includes the necessary patches to resolve the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share