MySQL local_infile is enabled

Restrict unnecessary file transfers on both the server and client when LOAD DATA LOCAL is not required.

Description

MySQL local_infile relates to LOAD DATA LOCAL, which transfers a file readable by the client to the server. Both server and client must permit the feature, and actual use also depends on SQL permissions and the client process’s file access.

This differs from reading arbitrary files on the database server. In particular, a client connected to an untrusted server can receive an unintended file-transfer request.

Potential impact

  • Sensitive files readable by the client may be transferred to the server.
  • Unneeded file-import functionality can increase the application’s attack surface.

Remediation

  • If it is not required, set local_infile to off in databaseFlags and restrict LOCAL support in the client too.
  • Where required, connect only to trusted servers and minimize accessible files and SQL permissions.
  • Preserve other required flags during the change and verify the actual setting and required import operations.

Examples

Deployment Manager support has ended. These are excerpts from a legacy MySQL 5.7 configuration. Check support and upgrade plans for the engine in use, and supply the tier, Region and other required settings through a supported management tool.

Before

yaml
resources:
  - name: db-instance
    type: sqladmin.v1beta4.instance
    properties:
      databaseVersion: MYSQL_5_7
      settings:
        databaseFlags:
          - name: local_infile
            value: "on"

The server permits local_infile. Client support and permissions are also required for a file transfer.

After

yaml
resources:
  - name: db-instance
    type: sqladmin.v1beta4.instance
    properties:
      databaseVersion: MYSQL_5_7
      settings:
        databaseFlags:
          - name: local_infile
            value: "off"

This disables server-side permission for LOCAL file loading. Review client settings and other data-import paths separately.

References