Apache · Apache Airflow Mysql Provider · CVE-2023-22884
**Name of the Vulnerable Software and Affected Versions**
Apache Airflow versions prior to 2.5.1
Apache Airflow MySQL Provider versions prior to 4.0.0
**Description**
The issue is related to the improper neutralization of special elements used in a command, which can lead to command injection. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
**Recommendations**
For Apache Airflow versions prior to 2.5.1, update to version 2.5.1 or later.
For Apache Airflow MySQL Provider versions prior to 4.0.0, update to version 4.0.0 or later.
As a temporary workaround, consider restricting access to sensitive commands and parameters to minimize the risk of exploitation.