Review Cloud SQL SQL Server error-information exposure

Reduce unnecessary error details returned to ordinary users.

Description

SQL Server trace flag 3625 masks parameters in some error messages returned to users outside the sysadmin role. Without it, those error details can remain visible.

The flag does not disable all tracing or remove every sensitive value. Application error handling and controls on log access are still needed.

Potential impact

  • Error details can reveal internal structure or assist further attacks.
  • Excessive restriction of error details can hinder diagnosis.

Remediation

  • Set the Cloud SQL 3625 flag to on and plan the required restart. Verify errors returned to ordinary users and the diagnostic workflow.
  • Avoid exposing unnecessary internal errors through the application, and restrict access to detailed logs and their retention.

Examples

These excerpts compare part of the instance settings. Use a supported engine version and SQL Server machine type, and supply var.sql_server_tier and omitted required inputs. Changing this flag does not require the engine-version change shown in the examples.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "sqlserver-instance"
  database_version = "SQLSERVER_2017_STANDARD"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "3625"
      value = "off"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "sqlserver-instance"
  database_version = "SQLSERVER_2019_STANDARD"
  region           = "us-central1"

  settings {
    tier = var.sql_server_tier

    database_flags {
      name  = "3625"
      value = "on"
    }
  }
}

Explanation:

  • Before: Error-parameter masking is disabled.
  • After: Masking of some error parameters is enabled. This does not anonymize every error or log.

References