logo

Database

Weak credential policy In mysql2

Description

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

Summary

A rogue MySQL server (or MITM) can force mysql2 to send credentials in plaintext by requesting an auth switch to mysql_clear_password. The driver complies without verifying that TLS is active.

Details

mysql_clear_password is registered as a default standard plugin in lib/commands/auth_switch.js (line 21). When a server sends an AuthSwitchRequest (0xFE) requesting mysql_clear_password, the driver executes it without checking for TLS. The plugin (lib/auth_plugins/mysql_clear_password.js) returns Buffer.from(password + '\0').

Note: caching_sha2_password plugin DOES check for SSL before sending cleartext (line 77). But mysql_clear_password has no such guard.

Attack Scenario

    Attacker operates rogue MySQL server or performs MITM

    Server advertises caching_sha2_password in handshake

    Client sends hashed auth response

    Server replies with AuthSwitchRequest to mysql_clear_password

    Client sends password in plaintext

    Attacker captures plaintext password

PoC

Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request.

Suggested Fix

Remove mysql_clear_password from standardAuthPlugins, or add a guard requiring TLS/unix socket before allowing cleartext auth.

Impact

    mysql2: 9M weekly downloads

    Any application connecting without TLS is vulnerable to credential theft

    Cloud environments with untrusted network paths are especially at risk

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions