PT-2026-102500 · Apache Airflow · Apache Airflow Teradata Provider
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-teradata versions prior to 3.7.0
Description
The compute-cluster example Dag in the Apache Airflow Teradata provider declares Dag Params as unconstrained free text. These values are templated directly into compute-cluster operators, which interpolate them into Teradata DDL (Data Definition Language). A user with permissions to trigger the Dag can provide SQL fragments that execute using the task's connection. Additionally, because the connection ID is a free-text Param, the user can redirect the task to any other connection defined in the deployment.
Recommendations
Upgrade to version 3.7.0 or later.
For users who copied the example Dag, apply constraints to the Params to use validated identifiers and a closed value set, and remove connection selection and free-form option strings from trigger-time input.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Teradata Provider