Skip to content
HighVulnerability

GHSA-mwwr-p57h-56pf: @bytebase/dbhub's read-only mode does not prevent database writes

Published
Record updated
View JSON
Affected
  • @bytebase/dbhub < 0.22.6
Fixed in
0.22.6
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

@bytebase/dbhub's `readonly = true` setting on the `execute_sql` tool does not make connections read-only. The PostgreSQL and SQLite connectors only apply database-level read-only mode when `config.readonly` is set, but `source.readonly` can never be populated, so that path never runs. Enforcement falls to a classifier that checks only each statement's leading keyword, so a `SELECT` calling functions such as `setval`, `lo_export`, `pg_read_file` or `dblink_exec` can write data, read or write server files, or execute commands. The HTTP transport is unauthenticated and binds to `0.0.0.0` by default.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.