Description
MySQL's LOAD DATA LOCAL reads a file on the connected client host and transfers it to the server. The client may be a user's computer or an application server. When local_infile is enabled and the client also permits local file loading, sensitive files may be transferred depending on the SQL executed and the client process's file permissions.
Disable local file loading on both the server and client when it is unnecessary. Where it is needed, restrict file access and the servers clients can trust.
Potential impact
- An attacker who can control the SQL being executed may cause files readable by the client process to be transferred to the database.
- A client connected to an untrusted server may receive an unintended file-transfer request.
Remediation
- If local imports are unnecessary, set
local_infileto the stringoffand disable local file loading in the client. First check the impact on existing import workflows. - Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in
google.cloud1.14.0 cannot update existing objects. Preserve other required settings when replacing the flag list. - If the feature is needed, restrict executable SQL and the files the client can read, and use TLS with server-identity verification. Confirm that required imports continue to work.
Examples
These historical examples use MYSQL_5_6. Check version support and settings for your environment before deployment, and quote flag strings such as "on" or "off".
First configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: MYSQL_5_6
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: local_infile
value: on
tier: db-n1-standard-1
state: present
This configuration allows local file imports on the server. Client settings and file-read permissions also need appropriate restrictions.
Comparison configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: MYSQL_5_6
name: '{{ resource_name }}-2'
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: local_infile
value: off
tier: db-n1-standard-1
state: present
This configuration disables local file imports on the server. Disable the feature in clients too, and verify that the change has been applied to the existing instance.