CVE-2025-50213

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:apache-airflow-providers-snowflake:*:*:*:*:*:*:*:*

History

11 Jul 2025, 18:36

Type Values Removed Values Added
First Time Apache apache-airflow-providers-snowflake
Apache
CPE cpe:2.3:a:apache:apache-airflow-providers-snowflake:*:*:*:*:*:*:*:*
References () https://github.com/apache/airflow/pull/51734 - () https://github.com/apache/airflow/pull/51734 - Issue Tracking, Patch
References () https://lists.apache.org/thread/2kqfmyt2pghg5f6797g8hzvq331v8qx3 - () https://lists.apache.org/thread/2kqfmyt2pghg5f6797g8hzvq331v8qx3 - Mailing List, Vendor Advisory

24 Jun 2025, 18:15

Type Values Removed Values Added
CWE CWE-75

24 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 08:15

Updated : 2025-07-11 18:36


NVD link : CVE-2025-50213

Mitre link : CVE-2025-50213


JSON object : View

Products Affected

apache

  • apache-airflow-providers-snowflake
CWE

No CWE.