Impact
MariaDB Connector/J fails to enforce the allowLocalInfile=false configuration when handling server‑initiated LOCAL INFILE packets. A compromised or rogue MariaDB server can echo the exact filename requested by a Java application that issues a LOAD DATA LOCAL INFILE COM_QUERY, and the driver will transmit that file to the client even though the local‑infile option is intended to be disabled. The server cannot redirect the request to an arbitrary path, so the disclosure is limited to files that the application is actively loading, resulting in the exposure of sensitive data that is already being processed by the client.
Affected Systems
The vulnerability affects MariaDB Corporation’s MariaDB Connector/J driver for Java. All releases prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9 are affected. Versions 2.7.14, 3.3.5, 3.4.3, and 3.5.9 or later contain the fix.
Risk and Exploitability
The CVSS score of 3.7 indicates moderate risk, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, implying no documented widespread attacks. Exploitation requires a malicious or compromised database server and an application that performs a LOAD DATA LOCAL INFILE request over an untrusted connection, which limits real‑world attack likelihood.
OpenCVE Enrichment
Github GHSA