Description
MySQL local_infile concerns transferring files from the client computer to the server through LOAD DATA LOCAL. Both server and client must permit the feature, and the process’s file access and SQL privileges also apply.
An untrusted server can request unintended file transfers from a client, so limit the connections and clients that need the feature. This differs from reading files on the server.
Potential impact
- Files readable by the client process can be transferred unintentionally.
- Disabling the feature indiscriminately can break legitimate file-loading workflows.
Remediation
- If local file loading is unnecessary, set
local_infiletooffand disable LOCAL capability in clients as well. - Where it is needed, verify the identity of a trusted server and minimize client file access and SQL privileges. Test required loading workflows after changes.
Examples
These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.
Before
hcl
resource "google_sql_database_instance" "db" {
name = "mysql-instance"
database_version = "MYSQL_8_0"
region = "us-central1"
settings {
database_flags {
name = "local_infile"
value = "on"
}
}
}
After
hcl
resource "google_sql_database_instance" "db" {
name = "mysql-instance"
database_version = "MYSQL_8_0"
region = "us-central1"
settings {
tier = "db-f1-micro"
database_flags {
name = "local_infile"
value = "off"
}
}
}
Explanation:
- Before: The server permits local file loading. Client settings and privileges are also needed to use it.
- After: Server-side permission for local loading is disabled. Other file-access permissions are not removed.