Description
SQL Server trace flag 3625 masks parameters in some error messages returned to users outside the sysadmin role. Without it, those error details can remain visible.
The flag does not disable all tracing or remove every sensitive value. Application error handling and controls on log access are still needed.
Potential impact
- Error details can reveal internal structure or assist further attacks.
- Excessive restriction of error details can hinder diagnosis.
Remediation
- Set the Cloud SQL
3625flag toonand plan the required restart. Verify errors returned to ordinary users and the diagnostic workflow. - Avoid exposing unnecessary internal errors through the application, and restrict access to detailed logs and their retention.
Examples
These excerpts compare part of the instance settings. Use a supported engine version and SQL Server machine type, and supply var.sql_server_tier and omitted required inputs. Changing this flag does not require the engine-version change shown in the examples.
Before
hcl
resource "google_sql_database_instance" "db" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2017_STANDARD"
region = "us-central1"
settings {
database_flags {
name = "3625"
value = "off"
}
}
}
After
hcl
resource "google_sql_database_instance" "db" {
name = "sqlserver-instance"
database_version = "SQLSERVER_2019_STANDARD"
region = "us-central1"
settings {
tier = var.sql_server_tier
database_flags {
name = "3625"
value = "on"
}
}
}
Explanation:
- Before: Error-parameter masking is disabled.
- After: Masking of some error parameters is enabled. This does not anonymize every error or log.