MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N상세 설명
Summary
MariaDB Connector/J does not enforce allowLocalInfile=false when
processing server-initiated LOCAL INFILE requests (protocol packet
type 0xfb). However, exploitation is constrained: the server can
only request the exact filename the client already included in its
LOAD DATA LOCAL INFILE query, it cannot redirect to arbitrary paths.
Details
When a client executes LOAD DATA LOCAL INFILE '/path/to/file', the
connector sends the filename to the server as part of the COM_QUERY.
A rogue or MitM server responds with a 0xfb packet echoing that
same filename. The connector, without checking allowLocalInfile,
transmits the file content.
The bypass is therefore limited to the file the application itself
intended to load. The attacker cannot escalate to other files
(e.g. /etc/passwd) unless the application's own query targets them.
The real-world risk is:
- An application that uses
LOAD DATA LOCAL INFILEon potentially
sensitive files (credentials, exports, configs) and connects over
an untrusted network. allowLocalInfile=falseis supposed to disable this entire
mechanism as a defense-in-depth measure, but the flag is ignored.
Impact
The security guarantee of allowLocalInfile=false is not upheld,
but practical exploitation requires both a MitM/rogue server and an
application that actively uses LOCAL INFILE on sensitive data.
Credit
Reported by tharavel
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 4
링크 내용 불러오는 중…