Описание
Unauthorized file access via CONNECT engine UDFs
Impact
CONNECT engine plugin included file access UDFs (json_file(), bson_file(), jfile_make(), bfile_make(), jbin_file()) that used to ignore both FILE privilege and secure_file_priv setting. This allowed an attacker to access files on file system (under the constraint of usual OS file permissions) that one was not authorized to.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
Uninstall CONNECT engine plugin, if you don't need it. Uninstall CONNECT file access UDFs if you need the engine, but don't use these UDFs.
References
https://jira.mariadb.org/browse/MDEV-40323
Credits
Duong Tran from CyStack
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2