216.73.217.22

CVE-2025-50213

· Published 24/06/2025 08:15 · Modified 24/06/2025 18:15

Labels: CVE-2025-50213 2025-06-24CVE-2025-50213CWE-75[email protected]

Essential information

Published
24/06/2025 08:15
Modified
24/06/2025 18:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apache / airflow providers snowflake cpe:2.3:a:apache:airflow_providers_snowflake:<6.4.0:*:*:*:*:*:*:*

References