Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.This vulnerability is considered low since it requires DAG code to use get_sqlalchemy_connection and someone with access to connection resources specifically updating the connection to exploit it.
This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1.
It is recommended to upgrade to a version that is not affected
{
"nvd_published_at": "2023-06-27T12:15:13Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-20"
],
"github_reviewed_at": "2023-06-30T20:26:33Z",
"severity": "MODERATE"
}