Description
MySQL local_infile relates to LOAD DATA LOCAL, which transfers a file readable by the client to the server. Both server and client must permit the feature, and actual use also depends on SQL permissions and the client process’s file access.
This differs from reading arbitrary files on the database server. In particular, a client connected to an untrusted server can receive an unintended file-transfer request.
Potential impact
- Sensitive files readable by the client may be transferred to the server.
- Unneeded file-import functionality can increase the application’s attack surface.
Remediation
- If it is not required, set
local_infiletooffindatabaseFlagsand restrict LOCAL support in the client too. - Where required, connect only to trusted servers and minimize accessible files and SQL permissions.
- Preserve other required flags during the change and verify the actual setting and required import operations.
Examples
Deployment Manager support has ended. These are excerpts from a legacy MySQL 5.7 configuration. Check support and upgrade plans for the engine in use, and supply the tier, Region and other required settings through a supported management tool.
Before
resources:
- name: db-instance
type: sqladmin.v1beta4.instance
properties:
databaseVersion: MYSQL_5_7
settings:
databaseFlags:
- name: local_infile
value: "on"
The server permits local_infile. Client support and permissions are also required for a file transfer.
After
resources:
- name: db-instance
type: sqladmin.v1beta4.instance
properties:
databaseVersion: MYSQL_5_7
settings:
databaseFlags:
- name: local_infile
value: "off"
This disables server-side permission for LOCAL file loading. Review client settings and other data-import paths separately.