Cloud SQL MySQL permits local file loading

LOAD DATA LOCAL transfers files from the client host to MySQL. Disable unnecessary imports and control client file access and server-identity verification.

Description

MySQL's LOAD DATA LOCAL reads a file on the connected client host and transfers it to the server. The client may be a user's computer or an application server. When local_infile is enabled and the client also permits local file loading, sensitive files may be transferred depending on the SQL executed and the client process's file permissions.

Disable local file loading on both the server and client when it is unnecessary. Where it is needed, restrict file access and the servers clients can trust.

Potential impact

  • An attacker who can control the SQL being executed may cause files readable by the client process to be transferred to the database.
  • A client connected to an untrusted server may receive an unintended file-transfer request.

Remediation

  • If local imports are unnecessary, set local_infile to the string off and disable local file loading in the client. First check the impact on existing import workflows.
  • Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in google.cloud 1.14.0 cannot update existing objects. Preserve other required settings when replacing the flag list.
  • If the feature is needed, restrict executable SQL and the files the client can read, and use TLS with server-identity verification. Confirm that required imports continue to work.

Examples

These historical examples use MYSQL_5_6. Check version support and settings for your environment before deployment, and quote flag strings such as "on" or "off".

First configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: MYSQL_5_6
    name: "{{ resource_name }}-2"
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: local_infile
        value: on
      tier: db-n1-standard-1
    state: present

This configuration allows local file imports on the server. Client settings and file-read permissions also need appropriate restrictions.

Comparison configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: MYSQL_5_6
    name: '{{ resource_name }}-2'
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: local_infile
        value: off
      tier: db-n1-standard-1
    state: present

This configuration disables local file imports on the server. Disable the feature in clients too, and verify that the change has been applied to the existing instance.

References