Weak credential policy In mysql2
Description
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
Summary
A rogue MySQL server (or MITM) can force mysql2 to send credentials in plaintext by requesting an auth switch to mysql_clear_password. The driver complies without verifying that TLS is active.
Details
mysql_clear_password is registered as a default standard plugin in lib/commands/auth_switch.js (line 21). When a server sends an AuthSwitchRequest (0xFE) requesting mysql_clear_password, the driver executes it without checking for TLS. The plugin (lib/auth_plugins/mysql_clear_password.js) returns Buffer.from(password + '\0').
Note: caching_sha2_password plugin DOES check for SSL before sending cleartext (line 77). But mysql_clear_password has no such guard.
Attack Scenario
Attacker operates rogue MySQL server or performs MITM
Server advertises caching_sha2_password in handshake
Client sends hashed auth response
Server replies with AuthSwitchRequest to mysql_clear_password
Client sends password in plaintext
Attacker captures plaintext password
PoC
Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request.
Suggested Fix
Remove mysql_clear_password from standardAuthPlugins, or add a guard requiring TLS/unix socket before allowing cleartext auth.
Impact
mysql2: 9M weekly downloads
Any application connecting without TLS is vulnerable to credential theft
Cloud environments with untrusted network paths are especially at risk
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.22.0 |
Aliases
References