VDB
Sign up
MEDIUM5.9

GHSA-42r5-vhpq-m858

MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials

Quick fix

GHSA-42r5-vhpq-m858 — mariadb: upgrade to the fixed version with the command below.

npm install mariadb@3.2.4

Details

### Summary

When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.

### Details

The mysql_clear_password plugin is gated behind a secure connection: the driver refuses to transmit the password in cleartext over plain TCP. The sibling PAM plugin handler (SendPamAuthPacketFactory, server-side plugin name dialog) did not override that gate and inherited the default value false, so it was not subject to the same secure-transport requirement.

As a result, a hostile or man-in-the-middle server can issue an Authentication Switch Request for the dialog plugin over plain TCP, and the driver responds with the user's password in cleartext. With the default configuration (sslMode=DISABLE, restrictedAuth=null) this is reachable with no non-default options.

### Am I affected?

You are affected if all of the following hold:

You use mariadb Connector/Node.js at a version below the patched release(s). Connections can occur over an insecure transport: plain TCP (sslMode=DISABLE), or a TLS mode that establishes server identity only via self-signed-certificate fingerprint validation. An attacker can occupy an on-path (MITM) position, or otherwise cause the client to connect to a server they control, and present an Authentication Switch Request for the dialog plugin.

Connections over properly verified TLS or a local Unix socket are not exposed to this vector.

### Impact

Disclosure of the authenticating account's password in cleartext to an on-path or hostile server. The captured credentials can then be reused to authenticate to the database (and, if reused elsewhere, beyond it).

### Patches

Fixed in 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Upgrade to the patched release on your branch (3.5.x → 3.5.3, 3.4.x → 3.4.6, 3.3.x → 3.3.3, 3.2.x and earlier → 3.2.4). PAM (dialog) is now treated exactly like mysql_clear_password: it may only run over a secure transport. SendPamAuthPacketFactory overrides the secure-required flag to true, and the authentication dispatcher permits a secure-required plugin only when the connection is TLS or a local Unix socket. The pre-existing check that blocks non-MITM-proof plugins when server identity relies solely on self-signed-certificate fingerprint validation continues to apply. Net effect: PAM is allowed over TLS or a Unix socket, and rejected over plain TCP or fingerprint-only connections.

### Workarounds

If you cannot upgrade immediately:

* Restrict the permitted authentication plugins via restrictedAuth so dialog cannot be negotiated over an insecure transport. Avoid PAM (dialog) authentication over plain TCP.

###Credit

Reported by Yalguun Tumenkhuu ([@fg0x0](https://github.com/fg0x0/)).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mariadb
Introduced in: 0Fixed in: 3.2.4
Fixnpm install mariadb@3.2.4
npm/mariadb
Introduced in: 3.3.0Fixed in: 3.3.3
Fixnpm install mariadb@3.3.3
npm/mariadb
Introduced in: 3.4.0Fixed in: 3.4.6
Fixnpm install mariadb@3.4.6
npm/mariadb
Introduced in: 3.5.0Fixed in: 3.5.3
Fixnpm install mariadb@3.5.3

References