Description
SQL Server ownership chaining can skip permission checks on a referenced object when it has the same owner as the referring object and the relevant conditions are met. If that chain crosses databases, it can permit access beyond the intended database boundary.
Cloud SQL has deprecated cross db ownership chaining for all SQL Server versions and no longer allows it to be newly set to on. Where it is already enabled, review application dependencies and remove the flag or change it to off.
Potential impact
- Ownership chaining combined with excessive database permissions can allow unintended access across databases or privilege escalation.
- Disabling a chain without accounting for dependent operations can break application workflows across databases.
Remediation
- Identify operations that need access across databases and review the associated account and object permissions. Remove the existing
cross db ownership chainingflag or set it to the stringoff. - Grant only the access those operations need. Consider certificate-signed stored procedures as recommended by Cloud SQL, and verify that required operations still work while unauthorized access is denied.
- Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in
google.cloud1.14.0 cannot update existing objects. Preserve other required flags when replacing the flag list.
Examples
These historical examples use SQLSERVER_13_1, which is not a currently documented Cloud SQL version identifier. The first example's on value also cannot be newly configured. Use a supported version and quoted flag strings such as "off" in an actual configuration.
First configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: SQLSERVER_13_1
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: cross db ownership chaining
value: on
tier: db-n1-standard-1
state: present
This historical configuration enables cross-database ownership chaining. If an existing instance uses it, review permissions across databases and application dependencies.
Comparison configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: SQLSERVER_13_1
name: '{{ resource_name }}-2'
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: cross db ownership chaining
value: off
tier: db-n1-standard-1
state: present
This configuration disables the flag. Provide the required access across databases separately and verify that normal operations continue to work.
References
- CWE-284
- Ansible gcp_sql_instance database_flags documentation
- google.cloud 1.14.0 SQL instance module implementation
- Cloud SQL for SQL Server flags and deprecation notice
- SQL Server cross-database ownership chaining
- Signing stored procedures with a certificate
- Cloud SQL for SQL Server instance settings
- SQL Server ownership chaining and permission checks