GHSA-cqhc-2h57-wpxf: High severity npm/mariadb vulnerability
Summary When SSL/TLS is enabled but no CA / server certificate is provided, the connector verifies the server's identity using fingerprint validation. The check is effective, the connection is ultimately rejected when it fails, but it happens after the authentication exchange. As a result, the credentials are sent before validation occurs, so an active man-in-the-middle who presents their own certificate receives the password in the handshake before the connection is aborted.
Impact The credentials are transmitted to the peer before the server's identity is validated. An on-path attacker (MitM) presenting any certificate can capture the account password, even though the connection then fails the fingerprint check and is closed. The disclosed credentials can subsequently be used to authenticate directly against the server.
- Attacker requirement: active man-in-the-middle position on the network path - Affected configuration: SSL/TLS enabled without a CA / server certificate
Affected versions - < 3.2.4 - 3.3.0 – 3.3.2 - 3.4.0 – 3.4.5 - 3.5.0 – 3.5.2
Patches Fixed in 3.2.4, 3.3.3, 3.4.6, and 3.5.3. Upgrade to one of these (or later) on your branch.
Workarounds Until you can upgrade, configure certificate verification explicitly, provide the server/CA certificate and use a verifying SSL mode (e.g. VERIFYCA / VERIFYFULL).
Reported by haaahaaahiihiiii (no GitHub account).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/mariadbto a version that resolves this vulnerability.Fixed in 3.5.3 - Upgrade
Upgrade
npm/mariadbto a version that resolves this vulnerability.Fixed in 3.4.6 - Upgrade
Upgrade
npm/mariadbto a version that resolves this vulnerability.Fixed in 3.3.3 - Upgrade
Upgrade
npm/mariadbto a version that resolves this vulnerability.Fixed in 3.2.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.2.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.3 - Configuration
If SSL/TLS is enabled, configure explicit certificate verification by providing the server/CA certificate and using a verifying SSL mode.
SSL/TLS configuration SSL/TLS enabled without a CA / server certificate = Provide a CA / server certificate (do not run with SSL/TLS enabled without CA/server certificate) - Configuration
Configure certificate verification explicitly using a verifying SSL mode, e.g., VERIFY_CA or VERIFY_FULL, so the connector validates the server identity before accepting credentials.
Connector SSL/TLS mode SSL/TLS verification mode = VERIFY_CA / VERIFY_FULL
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the npm/mariadb connector with SSL/TLS enabled but without a CA or server certificate are affected. The affected version ranges are versions before 3.2.4, 3.3.0 through 3.3.2, 3.4.0 through 3.4.5, and 3.5.0 through 3.5.2.
What does an attacker need to capture credentials?
An attacker needs an active man-in-the-middle position on the network path and must present their own certificate. The password is sent during authentication before the connector completes fingerprint-based server identity validation.
Does a failed fingerprint check prevent credential theft?
No. The connection is rejected and closed after the fingerprint check fails, but the credentials have already been transmitted to the attacker-controlled peer and may be used to authenticate directly to the server.
What versions contain the fix?
Upgrade to 3.2.4, 3.3.3, 3.4.6, or 3.5.3, or a later release on the applicable branch.